
The cloud computing model has completely transformed the way we think about IT security. In traditional infrastructure, the organisation was responsible for most aspects of data protection – from hardware to applications. In the cloud, this division is no longer so straightforward. As systems are migrated to SaaS, PaaS or IaaS environments, a shared responsibility model emerges, which defines which elements are secured by the provider and which remain the responsibility of the customer.
Understanding this model is one of the key elements of effective cloud security management, and its principles have been clarified in the ISO/IEC 27017 standard.
The shared responsibility model is based on the division of security-related tasks between the cloud service provider and the organisation using those services.
The cloud provider is usually responsible for:
The customer, on the other hand, is responsible for:
The boundary of responsibility varies depending on the model (SaaS, PaaS, IaaS), which is why a lack of clear understanding of this boundary often leads to security gaps.

One of the most common problems faced by organisations using the cloud is the mistaken assumption that the provider is responsible for the full security of the data. In practice, this leads to negligence on the part of the customer. Typical mistakes include:
ISO 27017 addresses these issues by providing detailed guidance on the division of responsibilities and recommended security measures. This enables organisations to better understand which areas require their active involvement.
Depending on the service model, the division of responsibilities may vary:
Examples of areas that an organisation should regularly review:
ISO 27017 helps to organise these activities and assign a clear framework of responsibilities to them, which significantly reduces the risk of errors arising from ambiguities in the cloud environment.