Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions source/docs/cloud/aws-shared-responsibility-model.html.md.erb
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: AWS cloud shared responsibility model
title: AWS Cloud shared responsibility model
last_reviewed_on: 2026-03-25
review_in: 12 months
---
Expand All @@ -23,13 +23,13 @@ Cabinet Office Digital Cloud provides these added-values activities and services

The management of a workload or service running on Cabinet Office AWS Cloud is a shared responsibility between

* **The service team (Tenant)**: The service team owns the AWS accounts and is accountable for the lifecycle of workloads hosted on AWS Cloud, whether delivered in-house or via outsourcing. They are responsible for incident response, security, day-to-day operations and vulnerability management of the services.
* **The Service team (Tenant)**: The service team owns the AWS accounts and is accountable for the lifecycle of workloads hosted on AWS Cloud, whether delivered in-house or via outsourcing. They are responsible for incident response, security, day-to-day operations and vulnerability management of the services.

* **CO:D platform engineering (COPE) team:** The COPE team in Cabinet Office Digital owns the Cabinet Office AWS organisation and management accounts; responsible for all activities related to the organisational platform, customisation of the AWS organisation and automation required to maintain a central platform. This includes the billing dashboard, integration with cyber security, account and user management, and platform optimisation. The COPE team also manages the AWS business case and contractual arrangements.
* **CO:D Platform Engineering (COPE) team:** The COPE team in Cabinet Office Digital owns the Cabinet Office AWS organisation and management accounts; responsible for all activities related to the organisational platform, customisation of the AWS organisation and automation required to maintain a central platform. This includes the billing dashboard, integration with cyber security, account and user management, and platform optimisation. The COPE team also manages the AWS business case and contractual arrangements.

* **CO:D finance team**: The finance team is responsible for paying AWS invoices, monitoring spend against budgets, and recharging AWS consumption back to the relevant business units. Access to AWS billing portal is provided
* **CO:D Finance team**: The finance team is responsible for paying AWS invoices, monitoring spend against budgets, and recharging AWS consumption back to the relevant business units. Access to AWS billing portal is provided

* **CO:D cyber security**: Provides proactive organisation-wide security monitoring and cyber incident response; defines the Security Control Policies; owns and operates the Splunk cyber monitoring tool, and leads platform security improvement work.
* **CO:D Cyber Security**: Provides proactive organisation-wide security monitoring and cyber incident response; defines the Security Control Policies; owns and operates the Splunk cyber monitoring tool, and leads platform security improvement work.

* **AWS (Supplier)**: Delivers the underlying AWS infrastructure and services to the general market; responsible for cloud security, availability and compliance of AWS platform components, and for coordinating security incidents affecting the cloud environment.

Expand Down
Loading