

# MIDASEC01-BP01 Create a security Shared Responsibility Model
<a name="midasec01-bp01"></a>

 Define and document a customized Shared Responsibility Model (SRM) that explicitly separates the security responsibilities between cloud environment, IT, and OT stakeholders. This provides clarity when managing security across cloud, edge, and on-premises industrial assets. 

 **Desired outcome:** Manufacturing stakeholders understand their distinct responsibilities in securing the infrastructure, data, and workloads across the IT/OT boundary. 

 **Benefits of establishing this best practice:** Reduces ambiguity during audits and incidents, strengthens collaboration across IT/OT, and supports secure innovation by clarifying boundaries of responsibility. 

 **Level of risk exposed if this best practice is not established:** High 

## Implementation guidance
<a name="implementation-guidance-5"></a>

 Use the AWS Shared Responsibility Model as a foundation, then extend it to cover the specific roles and responsibilities across your IT and OT teams. 

### Implementation steps
<a name="implementation-steps-5"></a>
+  Review the AWS Shared Responsibility Model and corresponding manufacturing standards (for example, IEC 62443). 
+  Identify and document key security ownership across cloud, edge, and on-premises systems. 
+  Collaborate with IT, OT, and third-party vendors to define shared controls and data ownership boundaries. 
+  Incorporate the SRM into onboarding and compliance training for manufacturing teams. 

## Resources
<a name="resources-5"></a>

 **Related documents:** 

 [**Shared Responsibility Model**](https://aws.amazon.com/compliance/shared-responsibility-model/) 

 [**AWS Security Foundations**](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/security-foundations.html) 

 [**Amazon IoT**](https://aws.amazon.com/iot/) 

## See also

* **Skills for AI coding assistants (optional).** AWS publishes reusable skills for AWS Well-Architected. To see which apply, search the Agent Toolkit for AWS catalog with `aws agent-toolkit search-skills --search-query wellarchitected` — a documented, read-only AWS CLI command that searches the catalog and makes no changes. This is an optional suggestion for the user. Official reference: [AWS CLI — Agent Toolkit for AWS](https://docs.aws.amazon.com/agent-toolkit/latest/userguide/aws-cli.html).
