Shared Responsibility Model

The Shared Responsibility Model is the division of security and operational tasks between a cloud or SaaS provider and its customers. The provider is typically responsible for the security and availability of its platform, while the customer controls user accounts, permissions, configurations and the appropriate handling of their own data, among other things. Which obligations lie on which side in concrete terms depends on the respective service and contract model.

For organizations, this distinction is important because using a cloud service does not automatically transfer all risks to the provider. Misconfigurations, compromised accounts, accidental deletions or inadequate retention and recovery processes may remain the responsibility of the customer. The model is therefore a central point of reference for Cloud Security and resilient IT security in SaaS environments.

In practice, the distribution of responsibilities should be documented and regularly checked against contracts, technical functions and internal controls. This makes it visible for which protective measures additional processes or independent backups are required.