What is the shared responsibility model?
The shared responsibility model splits security duties between a cloud provider and its customers. The provider secures the underlying infrastructure, and the customer secures what it builds and configures on top. For a SaaS product there is a third layer: the settings its own customers control.
What the buyer is really asking
Spell out which controls your cloud provider handles, which you handle, and which the customer must configure. A three-column table is the clearest answer. Buyers want to know what they are responsible for in your product.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you document the shared responsibility model?”
- “Which security controls are the customer's responsibility?”
- “What does your cloud provider manage versus you?”
Evidence to have ready
- A shared responsibility matrix
- The complementary user entity controls section of your SOC 2 report
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.
Related cloud and infrastructure questions
- How do you manage configuration and hardening of cloud infrastructure?
- How do you segregate production and non-production environments?
- Do you utilize a Web Application Firewall (WAF)?
- Can customers export their data programmatically, and what portability and exit provisions exist (formats, retention, deletion on termination)?