University of Adelaide · FACULTY OF COMPUTER SCIENCE

INFO 2004 Chap.7 Shared Responsibility, IAM and Compliance

- one subject, every graph, every model, every mark
7 Chapters9-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 7 of 14 · INFO 2004

Shared Responsibility, IAM and Compliance

Cloud security is shared, but the split is not a slogan and it changes with the service model. The source contrasts provider responsibility for security of the cloud with customer responsibility for security in the cloud and asks students to classify duties in two activities. It also states the broad gradient from responsibility for everything on premises toward responsibility mainly for content and access policies in SaaS.

This corpus does not include the promised IAM teaching pages. Users, groups, policies and MFA appear in workshop and practical titles, but no captured prose explains their mechanics. Accordingly, IAM is treated only as a responsibility question: who receives access, who approves it, which policy expresses the decision, and how compliance evidence is maintained. No policy syntax, identifiers or evaluation rules are invented.

Governance sets decisions; compliance checks obligations and evidence; tools support that work but do not transfer accountability.

In this chapter

What this chapter covers

  • 01

    Security of the cloud and security in the cloud

  • 02

    How the split changes with service model

  • 03

    A duty-classification method

  • 04

    IAM as an access-governance topic

  • 05

    Users, groups, policies and MFA as named practical scope

  • 06

    Compliance, governance and evidence

  • 07

    What must be confirmed on Canvas

Worked example · free

Allocate responsibilities for a managed application

Q [4 marks]. AskSia-authored practice weighting. A business uses a provider-managed application containing customer data. Classify responsibility for provider infrastructure, customer content, access decisions, account administration and compliance evidence without reconstructing a lost layer chart.
  • 1Place operation of the provider's underlying cloud infrastructure on the provider side.
  • 1Place customer content and business access-policy decisions on the customer side.
  • 1Treat account administration as customer governance even where the provider supplies the control interface.
  • 1Keep accountability for demonstrating applicable compliance with the organisation; provider evidence may support but not replace it.
The provider operates the service infrastructure, while the customer remains responsible for its content, access decisions, account governance and its own compliance case. The service model narrows technical work but does not erase customer accountability.
Sia tip — Distinguish providing a control from deciding and proving how that control is used.
Glossary

Key terms

Shared responsibility
A cloud security model in which provider and customer duties coexist and the split changes with service abstraction.
Security of the cloud
Provider-side responsibility for the cloud environment it operates.
Security in the cloud
Customer-side responsibility for its content, identities, access decisions and configuration within the service.
IAM
Identity and access management; named in the course's delivered workshop and practical scope, though its detailed teaching pages are absent here.
Governance
The decisions, ownership and oversight through which an organisation directs cloud use.
Compliance
Demonstrating that relevant obligations and controls are satisfied with suitable evidence.
MFA
Multi-factor authentication, named in the practical scope but not technically described in the captured pages.
FAQ

Shared Responsibility, IAM and Compliance FAQ

Who is responsible for security in cloud computing?

Both provider and customer, with the split depending on the service model and the duty being considered.

Does SaaS remove customer security responsibility?

No. The source's gradient still leaves the customer responsible for content and access policies.

Where are the IAM mechanics taught?

The captured materials contain workshop and practical titles but not the IAM teaching pages. Confirm the detailed content on Canvas.

Does a provider compliance tool make the customer compliant?

No. Tools can support evidence and control, while the organisation retains responsibility for its compliance case.

Study strategy

Assessment move

Practise with a two-column duty ledger, then add a third column for evidence. For every scenario, name the duty before allocating it and state how the service model changes the split. Keep IAM discussion at the captured level and maintain a Canvas gap list for users, groups, policies and MFA mechanics. That restraint is part of a correct source-grounded answer.

Working through Shared Responsibility, IAM and Compliance in INFO 2004? Sia is AskSia’s AI Computer Science tutor — ask any INFO 2004 Shared Responsibility, IAM and Compliance question and get a clear, step-by-step explanation grounded in how INFO 2004 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + your other University of Adelaide subjects - and 1,000+ Bibles across every Australian university.
Sia - your INFO2004 tutor, unlimited, worked the way the exam marks it
The full 9-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
Unlock the full INFO2004 Bible + your other University of Adelaide subjects
$0.99 Trial