Cloud service implementations involve a shared security responsibility model (SSRM) between the CSP and the CSC. Although specific details vary from service to service (e.g., depending on the cloud service model and the particular implementation), both CSPs and CSCs should have organizational policies and procedures that delineate how the SSRM should be documented, implemented, managed, communicated, enforced, and audited.
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the application of the Shared Security Responsibility Model (SSRM) within the organization. Review and update the policies and procedures at least annually.
Cloud service implementations involve a shared security responsibility model (SSRM) between the CSP and the CSC. Although specific details vary from service to service (e.g., depending on the cloud service model and the particular implementation), both CSPs and CSCs should have organizational policies and procedures that delineate how the SSRM should be documented, implemented, managed, communicated, enforced, and audited.
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the application of the Shared Security Responsibility Model (SSRM) within the organization. Review and update the policies and procedures at least annually.