A city migrates staff email to a SaaS provider. Under the cloud shared responsibility model, which split is most accurate?
Select an answer to reveal the explanation.
Short Explanation
Think of SaaS like renting a secure apartment building: the landlord hardens the building, but you still lock your door and control who gets keys. The city owns identities and the data in the boxes; the provider owns the app stack underneath. Mixing those up leaves the wrong team watching the wrong controls.
Full Explanation
Cloud shared responsibility matrices assign customer duties for identity, access, and data in SaaS while providers typically secure the managed application infrastructure. Municipal teams must still govern accounts, MFA, sharing, and data handling in the tenant. Assigning physical facility controls to the city for pure SaaS, or treating encryption and identity as non-customer concerns, misstates the model.