Compliance and the shared responsibility model
According to the shared responsibility model (as explained in Chapter 1, Introduction to Cloud Security), the cloud provider in infrastructure as a service/platform as a service (IaaS/PaaS) is responsible for the physical aspects of the cloud (from physical data centers, hardware, storage, network equipment, host servers, to virtualization).
Software as a service (SaaS) providers are also responsible for application layers (guest operating system (OS), managed databases, managed storage, application tier, and more). As customers, we expect our cloud providers to be both compliant with regulatory requirements (such as protecting credit card information in PCI DSS, protecting personally identifiable information (PII) in GDPR, and more) and to work according to the highest security standards (such as ISO 27001, SOC, and more).
When we as organizations serve customers, we need to be compliant with regulations (when dealing with financial...