Service model
Software as a service: the shared responsibility split
The provider runs the whole application. You still run who has an account and what role it holds, the tenant settings, what data you put in and how long it stays, and your side of every incident.
Of the 14 control areas: 1 yours, 8 shared, 5 the provider's, before any category moves the line.
Every control area
SaaS| Control area | Owner | Why, and the clause |
|---|---|---|
GOV Governance and policy | shared | Each party governs its own side: the provider the service it delivers, you which data and services you allow and who may procure them. The allocation between you has to be written down. ISO/IEC 27017 6.1.1 |
IAM Identity and access | shared | The provider runs the sign-in service and its administrative plane; who holds an account, which role it carries and whether a second factor is enforced are yours. ISO/IEC 27017 9.2.3 |
DAT Data classification and handling | yours | What the data is, how it is labelled and where it may go is yours on every model; the provider only tells you what labelling and location options the service offers. ISO/IEC 27017 8.2.2 |
KEY Encryption and keys | the provider's | The provider encrypts the application's data with keys it manages; a key you hold exists only where the service offers one and you turn it on. ISO/IEC 27017 10.1.2 |
NET Network security | the provider's | The provider runs the application's network end to end; you control only which addresses and devices may sign in, where the service offers it. ISO/IEC 27017 CLD.9.5.1 |
LOG Logging and monitoring | shared | The provider logs the platform and makes activity logs available; turning them on, sending them somewhere you keep and reviewing them is yours. ISO/IEC 27017 CLD.12.4.5 |
VUL Vulnerability and patch management | the provider's | The provider patches the application and everything under it; you keep only the devices and integrations that reach it. ISO/IEC 27017 12.6.1 |
CFG Configuration and hardening | shared | The provider hardens the platform it runs; every setting you choose in your tenancy, and a public or open default you leave on, is yours. ISO/IEC 27017 CLD.12.1.5 |
APP Application security | the provider's | The application is the provider's to build and test; your side is the integrations and extensions you add to it. ISO/IEC 27017 14.2.1 |
INC Incident response | shared | Both sides respond: the provider must report incidents affecting your data within the agreed time, and you must detect and handle incidents in what you run and report to the provider what affects its service. ISO/IEC 27017 16.1.2 |
BCP Business continuity and backup | shared | The provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1 |
PHY Physical and environmental | the provider's | The data centres, power, cooling, access to the floor and the disposal of retired media are the provider's; your evidence is its assurance report, not your own inspection. ISO/IEC 27017 11.2.7 |
SUP Supplier and subservice | shared | The provider must publish its side of the model and the suppliers behind the service; you must hold the matrix for your estate, read the provider's side and keep the agreement that binds both. ISO/IEC 27017 CLD.6.3.1 |
AIR AI use and data retention | shared | Retention and purpose settings in the service are yours to choose; how the provider itself retains and uses what you send is set by its terms, which you must read. ISO/IEC 27018 A.3.1 |
Service categories delivered this way by default
13- AI assistant in a SaaS suiteai services
- Identity provideridentity and security
- Security monitoringidentity and security
- CI/CD pipelinesdeveloper tooling
- Code hostingdeveloper tooling
- Email and collaboration suitebusiness applications
- CRMbusiness applications
- HR systembusiness applications
- Finance systembusiness applications
- Ticketing and service deskbusiness applications
- File sharing and e-signaturebusiness applications
- Patch managementoperations
- Endpoint managementoperations