Book an Appointment

Fundamentals of Cloud Security

How to secure responsibilities, identities and configurations in the cloud in a structured way – from the shared responsibility model to an organization-wide baseline.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

4areas always remain with the customer per Microsoft's responsibility matrix
500+experts prioritized the CSA Top Threats 2024
11threats prioritized in the 2024 edition
100+CIS Benchmarks for over 25 product families

Cloud adoption shifts the nature of security work: instead of hardening their own data centers, organizations manage configurations, identities and responsibilities on infrastructure operated by someone else. That is precisely where most problems arise today – the Cloud Security Alliance ranks misconfigurations as well as identity and access management in the top two spots of its Top Threats 2024. For each of these areas, however, established models and catalogues exist, from the shared responsibility model through the CIS Benchmarks to landing zone architectures. This article puts the fundamentals into perspective for decision-makers – vendor-neutral and organized around the question of who is responsible for what.

The Essentials at a Glance

Six topic blocks — tap to expand.

Shared responsibility by service model

Provider and customer share responsibility for security — exactly how depends on the service model. Tap a model.

Operating system with the customer
  • The customer is responsible for the operating system, network controls and applications.
  • Data, endpoints, accounts and access management remain with the customer — as in every model — along with configurations and settings.
Operating systemNetwork controlsApplicationsConfigurations

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Cloud Security Alliance · 2024

Top Threats to Cloud Computing 2024

Survey of more than 500 practitioners with eleven prioritized threats; misconfiguration and inadequate change control in first place, IAM second, insecure interfaces and APIs third.

Cloud Security Alliance · 2025

Top Threats to Cloud Computing - Deep Dive 2025

Analysis of eight real-world security incidents along the threat framework of the 2024 edition, each with an attack synopsis, threat model and control recommendations.

Microsoft Learn · 2026

Shared responsibility in the cloud

Responsibility matrix across on-premises, IaaS, PaaS and SaaS; data, endpoints, accounts and access management remain with the customer in every model.

Microsoft Learn (Cloud Adoption Framework) · 2025

What is an Azure landing zone?

Reference architecture with platform and application landing zones whose governance and security policies are inherited through the management group hierarchy.

Center for Internet Security (CIS) · 2026

CIS Benchmarks

More than 100 consensus-based configuration benchmarks for over 25 product families, including AWS, Azure, Google Cloud and Oracle Cloud Infrastructure.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Kriterienkatalog C5

Minimum requirements for secure cloud computing as the basis for standardized attestations; according to the BSI, fundamentally revised in 2025/26 (version C5:2026).

Where does your cloud environment stand today?

In a no-obligation initial consultation, we jointly assess how robust your division of responsibilities, identity governance and configuration baselines really are.