Cloud computing: service model, responsibility, and evidence
Distinguish SaaS, PaaS, and IaaS, map customer and provider responsibilities, and evaluate cloud-control evidence for ISC.
The decision that earns the point
Identify the objective before choosing the control
Cloud computing provides on-demand access to shared configurable computing resources. The service model changes the responsibility boundary: customers retain more infrastructure responsibility in IaaS, while providers manage more of the stack in PaaS and SaaS. The customer still owns responsibilities such as data classification, user access, configuration, vendor oversight, and complementary controls that the contract and service model leave with it.
Exam use
ISC can test cloud characteristics, IaaS, PaaS, SaaS, public and private deployment, shared responsibility, concentration risk, contracts, access, encryption, logging, resilience, and third-party assurance.
Your scratch-paper plan
Solve it in three moves
- 1
Identify the cloud model
Classify the service and deployment model from what the provider supplies and what the customer still operates.
NIST SP 800-145: The NIST Definition of Cloud Computing - 2
Map responsibilities explicitly
Assign identity, configuration, data, software, operating system, infrastructure, monitoring, backup, and response duties to the correct party.
NIST SP 800-144: Security and Privacy in Public Cloud Computing - 3
Evaluate evidence and gaps
Compare contracts, reports, configurations, logs, tests, and customer controls with the risks that remain after outsourcing.
NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
Worked problem
Work the facts before choosing the answer
A company moves payroll to a SaaS provider. The provider patches the application and infrastructure, while the customer provisions users and configures approval roles. A terminated payroll manager remains active for six weeks.
CPAPass exam analysis using the stated assumptions
Show the work
SaaS does not transfer the customer's user-lifecycle responsibility. Provider patch evidence cannot compensate for the customer's failure to remove a terminated user account promptly.
Rule source: NIST SP 800-144: Security and Privacy in Public Cloud ComputingAnswer
Identify a customer access-control deficiency, remove and investigate the account, and test the affected activity. Do not label the incident solely a vendor-control failure.
Rule source: NIST SP 800-144: Security and Privacy in Public Cloud ComputingDo it now
Test the same decision with a fresh question
Start with free ISC practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.
The trap and the repair
Common trap
Assuming the provider owns every control because the application is SaaS erases customer configuration, identity, data, oversight, and complementary-control duties. Treating a cloud certificate as proof for every risk is another scope error.
Repair
Draw the technology stack and put a named owner beside each control objective before evaluating assurance evidence.
Authority and scope boundary
NIST defines cloud models and provides security guidance, while the Blueprint controls ISC exam scope. This route owns CPA-ISC cloud responsibility and risk decisions, not vendor comparisons, general ITGC taxonomy, or SOC report interpretation.
2026 Uniform CPA Examination Blueprints and NIST SP 800-145: The NIST Definition of Cloud Computing were reviewed on 2026-08-14. Check a newer authority when the effective date or facts change.
Cloud responsibility stack
Outsourcing technology does not outsource accountability
Service models move operational layers, but every layer and control objective still needs a named owner and evidence.
| Cloud fact | Provider typically handles | Customer still must evaluate | Authority |
|---|---|---|---|
| IaaS | Physical facilities, hardware, and core virtualization | Operating systems, applications, identities, configurations, and data | NIST SP 800-144: Security and Privacy in Public Cloud Computing |
| PaaS | Infrastructure plus managed platform components | Application code, users, service settings, secrets, and data | NIST SP 800-144: Security and Privacy in Public Cloud Computing |
| SaaS | Application stack operation and underlying platform | User access, business configuration, data use, interfaces, and oversight | NIST SP 800-145: The NIST Definition of Cloud ComputingNIST SP 800-144: Security and Privacy in Public Cloud Computing |
| Any service model | Contracted availability and provider control commitments | Due diligence, complementary controls, monitoring, exit, and concentration risk | NIST SP 800-144: Security and Privacy in Public Cloud Computing |
After a miss
Review cloud questions with a responsibility stack
- 1
Classify the service and deployment model from the stated operating layers.
- 2
Assign each risk and control to provider, customer, or shared responsibility and name the evidence needed.
- 3
Work a fresh ISC cloud scenario and reject any answer that treats outsourcing as a transfer of accountability.
Your exam workflow
- Step 1Identify the requirementClassify the service and deployment model from what the provider supplies and what the customer still operates.NIST SP 800-145: The NIST Definition of Cloud Computing
- Step 2Classify the factsAssign identity, configuration, data, software, operating system, infrastructure, monitoring, backup, and response duties to the correct party.NIST SP 800-144: Security and Privacy in Public Cloud Computing
- Step 3Apply the authorityCompare contracts, reports, configurations, logs, tests, and customer controls with the risks that remain after outsourcing.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
- Step 4Check the outputIdentify a customer access-control deficiency, remove and investigate the account, and test the affected activity. Do not label the incident solely a vendor-control failure.NIST SP 800-144: Security and Privacy in Public Cloud Computing
Keep the next step narrow
Quick questions
What is the key rule?
Cloud computing provides on-demand access to shared configurable computing resources. The service model changes the responsibility boundary: customers retain more infrastructure responsibility in IaaS, while providers manage more of the stack in PaaS and SaaS. The customer still owns responsibilities such as data classification, user access, configuration, vendor oversight, and complementary controls that the contract and service model leave with it.
How can this topic be tested on the CPA Exam?
ISC can test cloud characteristics, IaaS, PaaS, SaaS, public and private deployment, shared responsibility, concentration risk, contracts, access, encryption, logging, resilience, and third-party assurance.
What mistake most often changes the result?
Assuming the provider owns every control because the application is SaaS erases customer configuration, identity, data, oversight, and complementary-control duties. Treating a cloud certificate as proof for every risk is another scope error. Draw the technology stack and put a named owner beside each control objective before evaluating assurance evidence.
Where should I practice the decision?
After the worked example, open the ISC free-practice link and work a fresh question that tests the same decision. If the miss depends on SOC 1 versus SOC 2, review that handoff before trying another set.