The cloud shared-responsibility model, in plain English
There is a diagram every cloud provider publishes, usually in a blog post from 2016, that splits security into 'ours' and 'yours'. It is a good diagram. It is also uselessly generic, because your responsibilities shift depending on whether you are using raw compute, a managed database, or someone's finished SaaS. Shared responsibility is not one line. It is a line that moves per service.
ISO 27017 takes that vague diagram and makes it specific and auditable. For every control, you record who operates it: the cloud service customer (that is you, abbreviated CSC), the cloud service provider (them, the CSP), or shared, where both of you do a piece and you note who does which.
The single most expensive four words in cloud security are 'we assumed they handled it'. The matrix exists so nobody ever has to assume.
A quick worked example
- Encryption at rest on a managed database: usually shared. The provider gives you the capability, you have to turn it on and manage the keys.
- Physical destruction of failed disks: CSP. You will never touch the hardware, so you rely on their certification, and for your data you lean on cryptographic erasure.
- Who can assume the admin role in your account: CSC, entirely. Nobody at the provider configured your IAM for you.
Why writing it down changes everything
Two things happen when you fill in a shared-responsibility matrix honestly. First, you find the gaps: the controls where both parties quietly assumed the other one had it. Those gaps are exactly where incidents live. Second, you hand your auditor and your customers a single, readable answer to 'how is your cloud secured', instead of a shrug and a link to a provider's marketing page.
In Compliance One the matrix is not a spreadsheet you maintain on the side. You set CSC, CSP or Shared on each control right where you work it, or manage the whole set in one grid with an export, and your continuous posture scans keep the technical controls evidenced underneath it. The line stops moving in the dark.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.