Parameter

What is Shared responsibility model?

What the cloud shared responsibility model is, where the provider's job ends and yours begins across IaaS, PaaS and SaaS, and where breaches happen.

01Introduction

Every major cloud provider publishes the same message in different words: we secure the cloud, you secure what you put in it. Most cloud breaches happen on the customer's side of that line.

02What is Shared responsibility model?

The shared responsibility model is the division of security duties between a cloud provider and its customer. The provider secures the physical data centers, hardware, hypervisor and core services. The customer secures identities, configuration, data, applications and, depending on the service, operating systems and networks.

The split shifts with the service model: customers own the most in IaaS, less in PaaS and least in SaaS, but identity and data are always the customer's. Categories such as CSPM, CIEM, DSPM and SSPM exist to cover the customer side.

03How Shared responsibility model works

The customer's share depends on how much of the stack they run.

  1. 1.

    IaaS

    You manage operating systems, patching, network rules, identities, applications and data. See patch management.

  2. 2.

    PaaS and containers

    The provider manages the runtime, you manage configuration, code, identities and data. See KSPM.

  3. 3.

    Serverless

    You own function code, permissions, triggers and the data they touch.

  4. 4.

    SaaS

    You own user access, sharing settings, integrations and data governance.

04Threats and risks

Breaches cluster where teams assume someone else is responsible.

  • Assumed defaults

    Believing the provider makes storage private or encrypts everything by default.

  • Misconfiguration

    Public resources and open network rules, the most common cause of cloud breaches.

  • Identity sprawl

    Over-permissioned roles that are always the customer's responsibility.

  • Compliance gaps

    Relying on the provider's certification for controls that frameworks such as SOC 2 and FedRAMP expect you to own.

05How Parameter helps

Parameter is built for the customer side of the line.

  • Your configuration

    Cloud Security finds the misconfigurations and identity paths in your AWS, Google Cloud, Azure and Oracle Cloud accounts.

  • Your applications

    The pentesting agents test the code you deploy on top of the provider.

  • Proof for auditors

    Evidence maps to frameworks on the compliance pages.

[ Cloud Security ]

See how Parameter Cloud Security fits your Shared responsibility model program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.