731 901 601
Shared responsibility in the cloud – a key element of ISO 27017

Shared responsibility in the cloud – a key element of ISO 27017

The cloud computing model has completely transformed the way we think about IT security. In traditional infrastructure, the organisation was responsible for most aspects of data protection – from hardware to applications. In the cloud, this division is no longer so straightforward. As systems are migrated to SaaS, PaaS or IaaS environments, a shared responsibility model emerges, which defines which elements are secured by the provider and which remain the responsibility of the customer.

Understanding this model is one of the key elements of effective cloud security management, and its principles have been clarified in the ISO/IEC 27017 standard.

How does the shared responsibility model work, and where are the boundaries?

The shared responsibility model is based on the division of security-related tasks between the cloud service provider and the organisation using those services.

 The cloud provider is usually responsible for:

  • the physical security of the infrastructure (server rooms, hardware),
  • the availability and stability of the platform,
  • baseline security (hypervisor, network, infrastructure).

The customer, on the other hand, is responsible for:

  • data management and classification,
  • configuration of services and user permissions,
  • access control to applications and resources,
  • data encryption and key management (depending on the service model).

The boundary of responsibility varies depending on the model (SaaS, PaaS, IaaS), which is why a lack of clear understanding of this boundary often leads to security gaps.

The most common mistakes and the role of ISO 27017 in addressing them

One of the most common problems faced by organisations using the cloud is the mistaken assumption that the provider is responsible for the full security of the data. In practice, this leads to negligence on the part of the customer. Typical mistakes include:

  • incorrect access configurations (e.g. overly broad permissions),
  • lack of control over user accounts and their lifecycle,
  • lack of data encryption or improper key management,
  • unclear policies on creating and restoring backups,
  • lack of monitoring of activity within the cloud environment.

ISO 27017 addresses these issues by providing detailed guidance on the division of responsibilities and recommended security measures. This enables organisations to better understand which areas require their active involvement.

Examples of responsibilities and a checklist for organisations

Depending on the service model, the division of responsibilities may vary:

  • SaaS: the provider manages almost all of the infrastructure; the customer is primarily responsible for data and users,
  • PaaS: the provider secures the platform; the customer is responsible for applications and data,
  • IaaS: the provider supplies the infrastructure, whilst the customer manages the operating systems, applications and data.

Examples of areas that an organisation should regularly review:

  1. whether access to resources is restricted in accordance with the principle of least privilege,
  2. whether data is encrypted in transit and at rest,
  3. whether backups are created and tested,
  4. whether security logs are collected and analysed,
  5. whether roles and permissions are up to date and regularly reviewed.

ISO 27017 helps to organise these activities and assign a clear framework of responsibilities to them, which significantly reduces the risk of errors arising from ambiguities in the cloud environment.

 

Read other posts

HACCP in the food service and catering industries – requirements that apply to every kitchen

HACCP in the food service and catering industries – requirements that apply to every kitchen

Restaurants, bars, canteens, catering companies, food trucks and shops selling food prepared on the premises – all these entities are food business operators within the meaning of Regulation (EC) No 852/2004 and are all required to apply HACCP principles. read more
BRCGS Packaging Materials Issue 7 – what has changed since April 2025?

BRCGS Packaging Materials Issue 7 – what has changed since April 2025?

From 28 April 2025, all audits of packaging materials manufacturers must be conducted in accordance with the new, seventh edition of the BRCGS Packaging Materials standard. read more
What is ISO 14001 and how can you implement this system in your company?

What is ISO 14001 and how can you implement this system in your company?

ISO 14001 is a standard that sets out the requirements an organisation must meet to effectively manage factors affecting the environment. read more
More posts