MIDASEC01-BP01 Create a security Shared Responsibility Model
Define and document a customized Shared Responsibility Model (SRM) that explicitly separates the security responsibilities between cloud environment, IT, and OT stakeholders. This provides clarity when managing security across cloud, edge, and on-premises industrial assets.
Desired outcome: Manufacturing stakeholders understand their distinct responsibilities in securing the infrastructure, data, and workloads across the IT/OT boundary.
Benefits of establishing this best practice: Reduces ambiguity during audits and incidents, strengthens collaboration across IT/OT, and supports secure innovation by clarifying boundaries of responsibility.
Level of risk exposed if this best practice is not established: High
Implementation guidance
Use the AWS Shared Responsibility Model as a foundation, then extend it to cover the specific roles and responsibilities across your IT and OT teams.
Implementation steps
-
Review the AWS Shared Responsibility Model and corresponding manufacturing standards (for example, IEC 62443).
-
Identify and document key security ownership across cloud, edge, and on-premises systems.
-
Collaborate with IT, OT, and third-party vendors to define shared controls and data ownership boundaries.
-
Incorporate the SRM into onboarding and compliance training for manufacturing teams.
Resources
Related documents: