INFO 2004 Chap.7 Shared Responsibility, IAM and Compliance
Shared Responsibility, IAM and Compliance
Cloud security is shared, but the split is not a slogan and it changes with the service model. The source contrasts provider responsibility for security of the cloud with customer responsibility for security in the cloud and asks students to classify duties in two activities. It also states the broad gradient from responsibility for everything on premises toward responsibility mainly for content and access policies in SaaS.
This corpus does not include the promised IAM teaching pages. Users, groups, policies and MFA appear in workshop and practical titles, but no captured prose explains their mechanics. Accordingly, IAM is treated only as a responsibility question: who receives access, who approves it, which policy expresses the decision, and how compliance evidence is maintained. No policy syntax, identifiers or evaluation rules are invented.
Governance sets decisions; compliance checks obligations and evidence; tools support that work but do not transfer accountability.
What this chapter covers
- 01
Security of the cloud and security in the cloud
- 02
How the split changes with service model
- 03
A duty-classification method
- 04
IAM as an access-governance topic
- 05
Users, groups, policies and MFA as named practical scope
- 06
Compliance, governance and evidence
- 07
What must be confirmed on Canvas
Allocate responsibilities for a managed application
- 1Place operation of the provider's underlying cloud infrastructure on the provider side.
- 1Place customer content and business access-policy decisions on the customer side.
- 1Treat account administration as customer governance even where the provider supplies the control interface.
- 1Keep accountability for demonstrating applicable compliance with the organisation; provider evidence may support but not replace it.
Key terms
- Shared responsibility
- A cloud security model in which provider and customer duties coexist and the split changes with service abstraction.
- Security of the cloud
- Provider-side responsibility for the cloud environment it operates.
- Security in the cloud
- Customer-side responsibility for its content, identities, access decisions and configuration within the service.
- IAM
- Identity and access management; named in the course's delivered workshop and practical scope, though its detailed teaching pages are absent here.
- Governance
- The decisions, ownership and oversight through which an organisation directs cloud use.
- Compliance
- Demonstrating that relevant obligations and controls are satisfied with suitable evidence.
- MFA
- Multi-factor authentication, named in the practical scope but not technically described in the captured pages.
Shared Responsibility, IAM and Compliance FAQ
Who is responsible for security in cloud computing?
Both provider and customer, with the split depending on the service model and the duty being considered.
Does SaaS remove customer security responsibility?
No. The source's gradient still leaves the customer responsible for content and access policies.
Where are the IAM mechanics taught?
The captured materials contain workshop and practical titles but not the IAM teaching pages. Confirm the detailed content on Canvas.
Does a provider compliance tool make the customer compliant?
No. Tools can support evidence and control, while the organisation retains responsibility for its compliance case.
Assessment move
Practise with a two-column duty ledger, then add a third column for evidence. For every scenario, name the duty before allocating it and state how the service model changes the split. Keep IAM discussion at the captured level and maintain a Canvas gap list for users, groups, policies and MFA mechanics. That restraint is part of a correct source-grounded answer.
Working through Shared Responsibility, IAM and Compliance in INFO 2004? Sia is AskSia’s AI Computer Science tutor — ask any INFO 2004 Shared Responsibility, IAM and Compliance question and get a clear, step-by-step explanation grounded in how INFO 2004 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.