Cloud Provider Shared Responsibility in TPRM
AWS: SOC 2, ISO 27001, FedRAMP. Enterprise Cloud Configuration: Public Buckets, Excessive Permissions, Logging Disabled.
4 min read · 4 June 2026 · Third-party oversight
The shared responsibility model , the framework through which cloud providers and their customers define which security responsibilities each party holds , is one of the most widely cited and most consistently misunderstood concepts in cloud security. Cloud provider security certifications (SOC 2, ISO 27001, FedRAMP) confirm the provider's security for the infrastructure and platform services they are responsible for. They do not confirm anything about the customer's security configuration of services on that infrastructure. When TPRM teams assess cloud provider relationships by reviewing the provider's certifications and confirming their security posture, they are confirming one side of a two-party security equation while leaving the other side , the enterprise's own configuration , unassessed.
The configuration responsibility boundary is the operationally critical detail. AWS is responsible for the security of its data centres, hypervisor infrastructure, managed service security, and the physical and network layers of its global infrastructure. AWS customers are responsible for the security of everything they deploy on AWS: their operating system configurations, application security, identity and access management policies, data encryption settings, network access controls, and monitoring configurations. A misconfigured IAM policy, a publicly accessible S3 bucket, or a disabled CloudTrail are customer configuration failures , they are not failures of AWS's security programme, and they are not visible in any AWS security certification.
Why this matters
Cloud shared responsibility matters for TPRM because the enterprise's actual cloud security depends on both sides of the shared responsibility model being correctly implemented , and TPRM assessments that evaluate cloud provider certifications without assessing enterprise cloud configuration are confirming half the security equation. Cloud Security Posture Management (CSPM) tools provide the missing assessment , evaluating the enterprise's own configuration of cloud services against security benchmarks.
- Cloud provider certifications accepted as cloud security confirmation
- Customer configuration responsibility not assessed alongside provider responsibility
- CSPM assessment absent from cloud security programme
- Shared responsibility boundary not documented for each cloud service in use
- Configuration drift creating ongoing exposure between assessments
What good looks like
Mature cloud security programmes assess both sides of the shared responsibility model , confirming cloud provider certifications for their scope while implementing CSPM tooling to continuously assess the enterprise's own cloud configuration against security benchmarks, with misconfiguration alerts and remediation workflows.
- Cloud provider certification review for provider-side responsibilities
- CSPM implementation for customer-side configuration assessment
- Shared responsibility mapping for each cloud service in use
- Continuous misconfiguration monitoring with remediation workflow
- CSPM findings in TPRM programme , customer configuration risk alongside provider risk
Tooling
CSPM , Wiz, Orca Security, Prisma Cloud, AWS Security Hub for cloud configuration assessment
Cloud Security Posture Management tools continuously assess cloud environment configurations against security benchmarks , CIS Benchmarks, cloud provider security standards, and custom policies , identifying misconfigurations, excessive permissions, and compliance gaps. For TPRM programmes, CSPM findings about customer configuration represent the enterprise's own contribution to cloud security risk alongside vendor-side assessment.
Governance challenges
The governance challenge with cloud shared responsibility in TPRM is the boundary ownership question. Cloud provider assessment is clearly a TPRM responsibility. Cloud configuration assessment is clearly a cloud security or IT responsibility. The gap between these two ownership domains , the shared responsibility model's customer side , may not be consistently owned by either team. CSPM implementation requires explicit ownership assignment.
- Assign ownership for customer-side cloud configuration security
- Implement CSPM for continuous configuration assessment
- Map shared responsibility boundary for each cloud service
- Include CSPM findings in cloud risk posture reporting
- Integrate CSPM alerts into remediation workflow
If you are a small team
Run one cloud configuration assessment using your cloud provider's native security tool , AWS Security Hub, Azure Security Center, or GCP Security Command Center. All three provide free-tier assessments of your cloud configuration against their security benchmarks. The findings will show you what your cloud configuration looks like from a security perspective, independent of what your cloud provider's certifications confirm about their side of the shared responsibility model.
- Run cloud provider native security tool assessment , AWS Security Hub, Azure Security Center
- Review findings against CIS Benchmark for your cloud services
- Separate provider-side and customer-side findings
- Implement CSPM for continuous configuration monitoring
What to require
Ask directly:
"For the cloud services we use through your platform , can you clarify which security responsibilities are yours under the shared responsibility model and which are ours, and do you provide tooling that helps us assess our configuration against security benchmarks?"
Expect as evidence
- Shared responsibility documentation for relevant services
- Customer-side security benchmark guidance
- Native CSPM or security assessment tooling
- Configuration security baseline documentation
A cloud provider who confirms strong security certifications should be asked for their shared responsibility model documentation. The certifications cover the provider side. The shared responsibility map reveals what the customer is responsible for , and therefore what TPRM should also be assessing.
How to evidence it
- Shared responsibility boundary documentation
- CSPM implementation records
- Configuration assessment findings
- Customer-side configuration security ownership
Key Takeaway
AWS: SOC 2, ISO 27001, FedRAMP , all confirmed. Enterprise cloud configuration: public S3 buckets, excessive IAM permissions, CloudTrail logging disabled, unencrypted data at rest. The enterprise assessed what AWS was responsible for. They did not assess what they themselves had configured. Cloud provider certification and customer configuration security are both sides of the same security equation. CSPM tools assess the customer side. Provider certifications assess the provider side. Both are required. Neither substitutes for the other.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association