When an organization engages a cloud provider, responsibility for activities and controls is shared between them, and they will agree a shared responsibility model.

In general the cloud provider is responsible for the underlying infrastructure, while the customer is responsible for data, applications and configurations. The precise division of responsibility will depend on the cloud service model (IaaS, PaaS, or SaaS), with the customer having greater management responsiblity and control with IaaS than PaaS and SaaS.

This can be illustrated in Microsoft’s ‘Division of Responsibility’ model diagram:

Division of Responsibility - Microsoft

Further reading