Prove the part your service performs. Name what remains with the customer.
A provider logo on a diagram proves nothing. The provider needs to identify the security function, evidence, limits, and customer configuration.
State what the service does and what the customer must do.
Provider evidence can support a customer’s claim. It does not prove how the customer configured or used the service, or determine the customer’s assessment result.
What you own. What others need from you.
The six roles perform different work and hold different authority. These are the facts this role has to supply, receive, and keep current.
- Owns
- The provider is responsible for accurately describing its service, people, hosting, data handling, configuration, and security work.
- Produces
- A current service description, customer responsibility matrix, operating evidence, known limits, and notices when the service changes.
- Receives
- The customer’s scope, intended use, information types, contract requirements, and the work the customer will perform.
- Rechecks when
- Notify affected customers when architecture, hosting, subprocessors, data paths, safeguards, responsibilities, or available evidence change.
Three ways to apply it.
- 01
State which assessment objectives the service supports and which remain with the customer.
- 02
Let authorized customers export the service facts an assessor needs; do not label raw telemetry as a passing finding.
- 03
Tell every affected customer when a service change may invalidate one of its claims.
Continue from this role.
Follow the shared Blueprint, examples, analysis, and current work that apply most directly to this part of the system.
- 01
Follow the operating loop
See where service facts and provider evidence enter the contractor’s security record.
- 02
Read the ecosystem principle
See why the proof crosses company lines while responsibility remains distinct.
- 03
Inspect a shared-responsibility example
Follow source, scope, coverage, owner, conflict, and reviewer in one record.
- 04
See how providers connect to the other roles
Follow provider responsibilities beside contractor, advisor, assessor, prime, and Government handoffs.
- 05
Test a service-evidence handoff
Bring a service export, customer responsibility boundary, or change event to a cross-role working session.
What does this role page miss?
Bring a real or synthetic handoff, conflict, responsibility boundary, or decision this model needs to handle.
Start a technical discussion