Understand the service layers
Infrastructure as a Service, or IaaS, provides an infrastructure layer on which the customer can run software. Platform as a Service, or PaaS, manages more of the supporting platform. Software as a Service, or SaaS, provides an application as a service. The exact boundaries depend on the offering.
Microsoft’s Azure responsibility matrix allocates operating systems, applications and infrastructure differently across these models. It also identifies continuing customer responsibilities for data, identities and configuration. Some areas are shared; the chart is not a universal contract. Shared responsibility in the cloud - Microsoft Azure
On-premises describes a hosting arrangement. It does not establish whether internal staff or a contracted provider performs every operational task.
Ask about activities, not just layers
For a useful conversation, name the activity: managing employee access, checking backups, maintaining an application or coordinating an incident. Then ask who carries it out, who makes the decision and what evidence demonstrates it has been done.
This proposed worksheet is a way to investigate the arrangement. It is not a standard allocation that every provider has accepted:
More columns to the right. Scroll to view.
| Activity | Question to resolve |
|---|---|
| Identity lifecycle | Who changes access, and who checks the application result? |
| Maintenance | Which operating systems and applications does each party maintain? |
| Recovery | Who protects recoverable copies and demonstrates a restore? |
| Incident coordination | Who must be contacted, and who may authorise action? |
| Exit | What can be exported, by whom and under what arrangements? |
Unassigned cells need a decision. Avoid replacing them with assumptions about what a provider “normally” does.
An invented evaluation example
A business compares a hosted application with a system operated at its own site. Instead of asking which label is safer, the evaluator asks both teams to explain backup ownership, access removal and incident contacts for the proposed arrangement.
The evaluator records “confirm” where evidence is missing. This example does not establish that either option meets the business’s needs or that a particular provider supplies backups, support or recovery commitments.
Keep contractual and privacy questions separate
A responsibility diagram is not a service-level agreement. Availability, support and recovery commitments need to be established from the actual agreement and service information.
Hosting terminology also does not determine privacy obligations. If personal information is involved, obtain advice about the applicable situation. The OAIC’s NDB overview concerns a particular Australian scheme; it does not settle every data-location or cross-border question. About the Notifiable Data Breaches scheme
Optional depth: a bounded AWS example
For Amazon EC2, AWS identifies the guest operating system, customer-installed applications and security-group configuration as customer responsibilities. It describes different responsibilities for more abstracted services. Do not copy the EC2 allocation to every AWS product. Shared Responsibility Model - Amazon Web Services (AWS)
A cloud or infrastructure architect should check the proposed service, configuration and dependencies. Procurement and legal reviewers should examine the agreement. This guide explains the ownership discussion; it does not decide whether cloud or on-premises is universally safer, cheaper or more suitable.
Related reading
- Configure, integrate or build: choosing the next software step — Compare broader software options without duplicating this responsibility discussion.
- Backups and restore tests — Examine backup and restore evidence.
- Evaluating IT and security suppliers — Assess supplier answers and commitments.