Cloud provider and customer share responsibility for security – exactly how depends on the service model. With IaaS, the customer is responsible for the operating system, network controls and applications; with PaaS, the provider takes over the operating system while application and network configuration remain shared; with SaaS, almost the entire stack sits with the provider. Regardless of the model, however, four areas always remain with the customer according to Microsoft's responsibility matrix: data, endpoints, accounts and access management – as do configurations and settings. The most common misconception is “the provider takes care of security”: particularly with SaaS, responsibility for access and configuration is regularly underestimated, and without explicit assignment, shared responsibilities remain effectively unowned.
Fundamentals of Cloud Security
How to secure responsibilities, identities and configurations in the cloud in a structured way – from the shared responsibility model to an organization-wide baseline.
Cloud adoption shifts the nature of security work: instead of hardening their own data centers, organizations manage configurations, identities and responsibilities on infrastructure operated by someone else. That is precisely where most problems arise today – the Cloud Security Alliance ranks misconfigurations as well as identity and access management in the top two spots of its Top Threats 2024. For each of these areas, however, established models and catalogues exist, from the shared responsibility model through the CIS Benchmarks to landing zone architectures. This article puts the fundamentals into perspective for decision-makers – vendor-neutral and organized around the question of who is responsible for what.
The Essentials at a Glance
Six topic blocks — tap to expand.
Shared responsibility by service model
Provider and customer share responsibility for security — exactly how depends on the service model. Tap a model.
- The customer is responsible for the operating system, network controls and applications.
- Data, endpoints, accounts and access management remain with the customer — as in every model — along with configurations and settings.
- The provider takes over the operating system while application and network configuration remain shared.
- Without explicit assignment, shared responsibilities remain effectively unowned.
- Almost the entire stack sits with the provider — yet data, endpoints, accounts and access management remain with the customer.
- The most common misconception is "the provider takes care of security": particularly with SaaS, responsibility for access and configuration is regularly underestimated.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Top Threats to Cloud Computing 2024
Survey of more than 500 practitioners with eleven prioritized threats; misconfiguration and inadequate change control in first place, IAM second, insecure interfaces and APIs third.
Top Threats to Cloud Computing - Deep Dive 2025
Analysis of eight real-world security incidents along the threat framework of the 2024 edition, each with an attack synopsis, threat model and control recommendations.
Shared responsibility in the cloud
Responsibility matrix across on-premises, IaaS, PaaS and SaaS; data, endpoints, accounts and access management remain with the customer in every model.
What is an Azure landing zone?
Reference architecture with platform and application landing zones whose governance and security policies are inherited through the management group hierarchy.
CIS Benchmarks
More than 100 consensus-based configuration benchmarks for over 25 product families, including AWS, Azure, Google Cloud and Oracle Cloud Infrastructure.
Kriterienkatalog C5
Minimum requirements for secure cloud computing as the basis for standardized attestations; according to the BSI, fundamentally revised in 2025/26 (version C5:2026).
Related Services
Where does your cloud environment stand today?
In a no-obligation initial consultation, we jointly assess how robust your division of responsibilities, identity governance and configuration baselines really are.