What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Moving workloads to a public cloud changes where security controls are implemented; it does not transfer your organization’s accountability for protecting its data and applications. The provider secures parts of the cloud service, while your team configures and operates the controls that remain yours. The division depends on whether you use IaaS, PaaS, or SaaS—and on the specific service.
What is security in the public cloud?
Public-cloud security is the combination of policies, practices, controls, and technologies used to protect cloud applications, data, and infrastructure. It includes technical safeguards as well as the processes that determine who can access systems, how information is handled, and how activity is governed and monitored. Google Cloud’s cloud-security explainer describes security as a shared effort between provider and customer.
For administrators, the practical scope commonly includes identity and access, data protection, workload and network configuration, governance, visibility, and ongoing security operations. Which party implements a particular control depends on the service model and the service’s own design.
Who is responsible for security in the cloud?
Responsibility is divided, but organizational accountability is not handed off. Providers generally protect the underlying cloud infrastructure; customers remain responsible for their data, access policies, and the customer-managed parts of their workloads. The balance shifts with the service model, and the exact boundary varies by provider and individual service.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
Tim Grance, identified by NIST as a co-author of its cloud-computing guidance, put the accountability point this way: “Public cloud computing and the other deployment models are a viable choice for many applications and services. However, accountability for security and privacy in public cloud deployments cannot be delegated to a cloud provider and remains an obligation for the organization to fulfill.” (NIST announcement.)
What does shared responsibility mean for IaaS, PaaS, and SaaS?
The more of the technology stack a provider operates, the fewer underlying layers the customer typically configures. The following is a general pattern, not a universal responsibility matrix. Check the provider’s current documentation for each service before assigning control ownership.
Rank #2
| Service model | What the provider generally operates | What the customer generally configures or maintains | Verification need |
|---|---|---|---|
| IaaS | Underlying cloud infrastructure. | More of the workload stack, including operating systems, applications, virtual network controls, identity, and data. | Confirm the boundary for each service; customer configuration and maintenance duties are comparatively broad. |
| PaaS | Underlying infrastructure and more of the platform, including operating-system responsibilities. | Applications, data, and access, plus any other customer-managed settings specified for the service. | Check which platform components and settings the service manages and which remain configurable by your team. |
| SaaS | More of the technology stack than in IaaS or PaaS. | Protecting the organization’s data and controlling who can use the service, along with customer-managed settings. | Verify the service’s data, identity, and administrative controls rather than assuming the provider handles them. |
This comparison reflects the general model described in Google Cloud’s explainer and its shared-responsibility guidance. It is not a substitute for the documentation of the provider and service you actually use.
What should IT admins secure when using a public cloud?
Start from organizational requirements, then map each requirement to the party and team responsible for implementing it. NIST’s SP 800-144 addresses outsourcing data, applications, and infrastructure to a public cloud and identifies system and network administrators among its audience. Its practical starting points are:
Recommended Free Tools
- Plan security and privacy before implementation. Identify what the workload must protect and the requirements it must meet before selecting configurations or deploying resources.
- Understand the provider environment. Learn how the particular provider and service work, including the boundary between provider-operated and customer-managed controls.
- Check resources and applications against organizational requirements. Review the deployed configuration and operating practices, not just the provider’s general security claims.
- Maintain accountability after deployment. Keep responsibility for the organization’s data and applications explicit as workloads change and services are operated.
These are planning principles, not a complete current control checklist. NIST published SP 800-144 in December 2011; the publication record describes its scope at NIST CSRC, and NIST’s announcement was published January 24, 2012 and updated February 3, 2025. Apply the guidance alongside current service documentation and the requirements that govern your organization.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can admins build security into cloud design and operations?
Set secure defaults and design controls in from the start
Security is easier to operate when it is part of system design rather than an afterthought. Google Cloud recommends security by design and secure defaults in its security-by-design guidance. Treat this as Google Cloud’s provider guidance, not as a claim that every platform implements the same blueprint. For your environment, translate the principle into decisions about identity, data handling, network and workload configuration, governance, and visibility before the system is in production.
Use a foundation for consistent governance and visibility
A cloud foundation can help an organization apply governance and security controls consistently, improve visibility, scale shared services, and give teams a common operating base. Google Cloud’s enterprise foundations blueprint is one provider-specific reference for architects, security practitioners, and platform engineering teams; it was last reviewed May 15, 2025 UTC. Its recommendations are relevant to Google Cloud environments and should not be treated as a neutral, cross-cloud standard.
Keep ownership clear in day-to-day operations
For each workload, make the service boundary operational: document who owns each customer-managed control, who reviews it, and how changes are checked against requirements. Revisit the mapping when the service or workload changes. The provider’s managed responsibility may reduce the layers your team operates, but it does not remove the need to govern customer data, application use, and access.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

