Concept and mechanism
Start by identifying the asset, threat, control, and accountable owner. Moving an application from VMs to PaaS changes who manages the operating system but does not eliminate decisions about data and access. A responsibility matrix should connect every control to execution, evidence, and escalation. Governance establishes who decides and follows up; risk management assesses uncertainty and impact; compliance examines applicable requirements. Buying a product does not automatically perform these functions. Defense in depth combines measures that remain useful when another fails. Zero Trust requires explicit verification, least privilege, and preparation for compromise; being inside a VPN does not justify universal access.
Guided application
In a fictional payments application, separate authenticating a person from authorizing payment approval. Recording a successful login does not prove that the account should hold that privilege. Identify who approves access, when it ends, and how it is reviewed. Also distinguish encryption, which permits data recovery with the appropriate key, from hashing, which produces a digest and does not recover the original. Comparing a hash only helps assess integrity when the reference is trustworthy. At handover, ask for evidence that RUN can perform assigned controls. A cloud-service list does not replace a procedure the team can apply during its actual shift.
The application moved to PaaS; a data-access owner is still needed.
Common pitfalls
Cloud as total transfer; VPN as absolute trust; authentication as authorization; hashing as encryption.
Related topics: Entra: access and privileges · Infrastructure protection
Connect each control to a need and an owner able to operate it.
Reference: Cloud shared responsibility · SC-900 objectives 2026-07-28; October 2026 update announced