With the rapid expansion of cloud adoption in both the public and private sectors, and the growing prevalence of hybrid and multi-cloud architectures, the “shared responsibility model” has become a common reference for allocating security and oper...
With the rapid expansion of cloud adoption in both the public and private sectors, and the growing prevalence of hybrid and multi-cloud architectures, the “shared responsibility model” has become a common reference for allocating security and operational duties among cloud service providers (CSPs), customer organizations, and third parties. However, high-level descriptions of shared responsibility in guidelines and certification schemes often leave practical “control gaps” in which ownership of key security controls is unclear, overlapping, or fragmented. Misconfigurations, over-privileged identities, and unmonitored SaaS or backup services in recent incidents illustrate that such gaps can be directly linked to real-world breaches. This study conceptualizes these control gaps from a shared responsibility perspective and examines how they appear in Korea’s national cloud security guidance compared with major international frameworks.
The research employs a structured document review and qualitative comparative analysis. First, it defines a multidimensional analytical matrix that crosses service models (IaaS, PaaS, SaaS), deployment models (public, private, hybrid, multi-cloud), security control domains (governance and organization; infrastructure and network; virtualization and platform; data and application; identity and access management; logging, monitoring, and incident response), and responsible entities (customer organization, CSP, third party). Using this matrix, the study maps and compares security controls across Korea’s national cloud computing security guideline and cloud security certification scheme, and overseas indicators including NIST and NSA/CISA guidance, FedRAMP, DoD SRG, CSA Cloud Controls Matrix, and ISO/IEC 27017/27018. The analysis is further interpreted through the lens of zero trust architecture, focusing on identity- and log-centric controls.
The results show that the Korean guideline functions effectively as a minimum baseline checklist for public agencies, but offers limited explicit modeling of which party holds primary, shared, or supporting responsibility for individual controls, especially in complex hybrid and multi-cloud settings. In contrast, overseas frameworks tend to provide more granular control catalogues, explicit role–control mappings, and, in many cases, risk- and maturity-based models that can guide stepwise improvement.
The study identifies notable control gaps around hybrid and multi-cloud governance, SaaS and backup services, third-party managed security and integrated monitoring, and zero-trust-related identity and logging controls. It suggests complementing the national guideline with responsibility matrices and maturity-oriented checklists derived from international frameworks to reduce control gaps and strengthen cloud security governance in the public sector.