Objective CLD.6.3 (the customer and provider relationship): make clear how the two parties share roles and responsibilities for managing information security. Control, in substance: both parties are to assign each shared information security role for the cloud service to a named party, record that assignment, tell those concerned, and put it into effect. Cloud service customer: define new policies and procedures, or extend existing ones, to fit how it uses cloud services, and make sure the people who use the service know what their roles and responsibilities are. Cloud service provider: document and communicate its information security capabilities, roles and responsibilities for the use of its service, together with the roles and responsibilities the customer needs to implement and manage as part of its use. Other information: roles are usually split between both parties' staff, and the allocation should take account of customer data and customer applications the provider hosts.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.