ISC exam skill

Cloud computing: service model, responsibility, and evidence

Distinguish SaaS, PaaS, and IaaS, map customer and provider responsibilities, and evaluate cloud-control evidence for ISC.

The decision that earns the point

Identify the objective before choosing the control

Cloud computing provides on-demand access to shared configurable computing resources. The service model changes the responsibility boundary: customers retain more infrastructure responsibility in IaaS, while providers manage more of the stack in PaaS and SaaS. The customer still owns responsibilities such as data classification, user access, configuration, vendor oversight, and complementary controls that the contract and service model leave with it.

Exam use

ISC can test cloud characteristics, IaaS, PaaS, SaaS, public and private deployment, shared responsibility, concentration risk, contracts, access, encryption, logging, resilience, and third-party assurance.

Check the official exam scope

Your scratch-paper plan

Solve it in three moves

  1. 1

    Identify the cloud model

    Classify the service and deployment model from what the provider supplies and what the customer still operates.

    NIST SP 800-145: The NIST Definition of Cloud Computing
  2. 2

    Map responsibilities explicitly

    Assign identity, configuration, data, software, operating system, infrastructure, monitoring, backup, and response duties to the correct party.

    NIST SP 800-144: Security and Privacy in Public Cloud Computing
  3. 3

    Evaluate evidence and gaps

    Compare contracts, reports, configurations, logs, tests, and customer controls with the risks that remain after outsourcing.

    NIST SP 800-53 Rev. 5.1: Security and Privacy Controls

Worked problem

Work the facts before choosing the answer

A company moves payroll to a SaaS provider. The provider patches the application and infrastructure, while the customer provisions users and configures approval roles. A terminated payroll manager remains active for six weeks.

CPAPass exam analysis using the stated assumptions

Show the work

SaaS does not transfer the customer's user-lifecycle responsibility. Provider patch evidence cannot compensate for the customer's failure to remove a terminated user account promptly.

Rule source: NIST SP 800-144: Security and Privacy in Public Cloud Computing

Answer

Identify a customer access-control deficiency, remove and investigate the account, and test the affected activity. Do not label the incident solely a vendor-control failure.

Rule source: NIST SP 800-144: Security and Privacy in Public Cloud Computing

Do it now

Test the same decision with a fresh question

Start with free ISC practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.

The trap and the repair

Common trap

Assuming the provider owns every control because the application is SaaS erases customer configuration, identity, data, oversight, and complementary-control duties. Treating a cloud certificate as proof for every risk is another scope error.

Repair

Draw the technology stack and put a named owner beside each control objective before evaluating assurance evidence.

Authority and scope boundary

NIST defines cloud models and provides security guidance, while the Blueprint controls ISC exam scope. This route owns CPA-ISC cloud responsibility and risk decisions, not vendor comparisons, general ITGC taxonomy, or SOC report interpretation.

2026 Uniform CPA Examination Blueprints and NIST SP 800-145: The NIST Definition of Cloud Computing were reviewed on 2026-08-14. Check a newer authority when the effective date or facts change.

Cloud responsibility stack

Outsourcing technology does not outsource accountability

Service models move operational layers, but every layer and control objective still needs a named owner and evidence.

Cloud factProvider typically handlesCustomer still must evaluateAuthority
IaaSPhysical facilities, hardware, and core virtualizationOperating systems, applications, identities, configurations, and dataNIST SP 800-144: Security and Privacy in Public Cloud Computing
PaaSInfrastructure plus managed platform componentsApplication code, users, service settings, secrets, and dataNIST SP 800-144: Security and Privacy in Public Cloud Computing
SaaSApplication stack operation and underlying platformUser access, business configuration, data use, interfaces, and oversightNIST SP 800-145: The NIST Definition of Cloud ComputingNIST SP 800-144: Security and Privacy in Public Cloud Computing
Any service modelContracted availability and provider control commitmentsDue diligence, complementary controls, monitoring, exit, and concentration riskNIST SP 800-144: Security and Privacy in Public Cloud Computing

After a miss

Review cloud questions with a responsibility stack

  1. 1

    Classify the service and deployment model from the stated operating layers.

  2. 2

    Assign each risk and control to provider, customer, or shared responsibility and name the evidence needed.

  3. 3

    Work a fresh ISC cloud scenario and reject any answer that treats outsourcing as a transfer of accountability.

Your exam workflow

  1. Step 1Identify the requirementClassify the service and deployment model from what the provider supplies and what the customer still operates.NIST SP 800-145: The NIST Definition of Cloud Computing
  2. Step 2Classify the factsAssign identity, configuration, data, software, operating system, infrastructure, monitoring, backup, and response duties to the correct party.NIST SP 800-144: Security and Privacy in Public Cloud Computing
  3. Step 3Apply the authorityCompare contracts, reports, configurations, logs, tests, and customer controls with the risks that remain after outsourcing.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
  4. Step 4Check the outputIdentify a customer access-control deficiency, remove and investigate the account, and test the affected activity. Do not label the incident solely a vendor-control failure.NIST SP 800-144: Security and Privacy in Public Cloud Computing

Quick questions

What is the key rule?

Cloud computing provides on-demand access to shared configurable computing resources. The service model changes the responsibility boundary: customers retain more infrastructure responsibility in IaaS, while providers manage more of the stack in PaaS and SaaS. The customer still owns responsibilities such as data classification, user access, configuration, vendor oversight, and complementary controls that the contract and service model leave with it.

How can this topic be tested on the CPA Exam?

ISC can test cloud characteristics, IaaS, PaaS, SaaS, public and private deployment, shared responsibility, concentration risk, contracts, access, encryption, logging, resilience, and third-party assurance.

What mistake most often changes the result?

Assuming the provider owns every control because the application is SaaS erases customer configuration, identity, data, oversight, and complementary-control duties. Treating a cloud certificate as proof for every risk is another scope error. Draw the technology stack and put a named owner beside each control objective before evaluating assurance evidence.

Where should I practice the decision?

After the worked example, open the ISC free-practice link and work a fresh question that tests the same decision. If the miss depends on SOC 1 versus SOC 2, review that handoff before trying another set.

Sources behind the rule