ClearPenTest

Audit and compliance

Shared responsibility model

Also called: cloud shared responsibility

The shared responsibility model is the division of security duties between a cloud provider and its customer. The provider secures the underlying infrastructure; the customer secures configuration, identity, access and data. A provider's own compliance certifications do not transfer to the customer's system.

The recurring error is treating a provider's SOC 2 as covering your product. It covers their infrastructure. Your configuration, your access model and your application are yours to evidence.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.