Cloud Security/ Shared Responsibility Matrix
🤝 Responsibility Model

Shared Responsibility
Matrix — IaaS · PaaS · SaaS

Interactive matrix showing exactly what you own vs what AWS, Azure, and GCP own — across IaaS, PaaS, and SaaS service models. Select a service model and provider to drill into specific responsibilities, common misunderstandings, and required customer controls.

3
Providers
IaaS
EC2/VM/GCE
PaaS
RDS/App Svc
SaaS
O365/Workspace
Interactive Responsibility Matrix
Customer You own and must configure
Provider Cloud provider manages
Shared Jointly owned — both parties have obligations
N/A Not applicable to this model

Detail

Most Dangerous Misconceptions
Myth vs Reality

"The cloud is secure by default"

Cloud providers secure their infrastructure — you are responsible for everything you deploy on top of it. Misconfigurations (public S3 buckets, open security groups) are entirely your responsibility.

Reality: 99% of cloud breaches through 2025 were caused by customer misconfigurations (Gartner)
Myth vs Reality

"Provider encrypts my data automatically"

Providers may encrypt at rest by default, but they hold the keys. You need BYOK/CMK to prevent provider access. Key management is always a customer responsibility.

Risk: Provider employee, legal compulsion, or compromise = access to your data without BYOK
Myth vs Reality

"SaaS = zero security responsibility"

In SaaS you still own: data governance, access controls, user provisioning/deprovisioning, DLP settings, conditional access, sharing permissions, and compliance classification.

M365/Workspace breach paths: compromised admin accounts, over-shared SharePoint, no DLP
Myth vs Reality

"PaaS patches itself, no patching needed"

Providers patch the platform (OS, runtime). You patch the application code, libraries, and containers you deploy on PaaS. Application-layer CVEs remain your responsibility.

Log4Shell affected PaaS customers — AWS/Azure patched infrastructure but customer apps still vulnerable
Shared Complexity

Network Security Groups / Firewalls

Providers supply the firewall tooling (SGs, NSGs, VPC Firewall Rules). Configuration of rules — what's allowed and denied — is entirely your responsibility. Default: often too permissive.

Always start with deny-all, add explicit allow rules. Review quarterly.
Shared Complexity

Identity & Access in PaaS

Provider manages the IAM service. You manage: user accounts, role assignments, permission boundaries, MFA enforcement, and conditional access policies. A compromised admin = provider infra can't help you.

Entra ID breach: Microsoft's infrastructure is fine, your tenant and data are exposed
What Do I Actually Own? — Deep Dive Tool

🔍 Customer Responsibility Breakdown

Select a provider and service type. Get a concrete list of every control the customer owns, common gaps seen in incident response, and the specific cloud service/setting to configure.