← CCSP: cloud security, data, and operations
01 / 8 · 50 MIN

Architecture, responsibilities, and portability

Assess the complete service, including dependencies and exit conditions.

Concept and mechanism

A cloud service combines provider controls with customer decisions. The contracted model distributes tasks but does not remove the need for data authorization and correct configuration. In SaaS, a customer-created public link can expose documents despite protected infrastructure. In PaaS, the provider may maintain the operating system while the application remains responsible for tenant separation. Record who configures, operates, verifies, and decides each control. Also distinguish interoperability, enabling services to communicate, from portability, enabling data and functions to move with meaning preserved. An API or CSV export does not alone establish that the process can be reconstructed at another provider.

Guided application

In a fictional funds project, an exit rehearsal exports records but loses relationships and permissions. Keep acceptance pending until conversion is defined and the destination validated with representative data. BIA should include external dependencies, such as files arriving only after technical recovery. Two providers may share an IdP and secrets repository, retaining a common failure. Specific protections also have limits: confidential computing protects data in use but does not fix application authorization. An AI agent reading documents should not turn retrieved text into tool authority. When assessing provider assurance, confirm service, period, and scope; a report about other products is not automatic evidence for the selected platform.

IN PRACTICE

Export completed without relationships or permissions: transfer demonstrated, functional portability pending.

Common pitfalls

SaaS as zero responsibility; API as portability; two providers as independence; out-of-scope assurance.

Related topics: Versions, retention, and holds · Data protection, location, and classification · Infrastructure, isolation, and recovery

Take this idea with you

Assess what must work, who controls it, and how it will be transferred.

Create account

Reference: Security and privacy in public cloud · CCSP examination outline effective 2026-08-01; January2026 V2 PDF