Shared responsibility should name the seam
Most failures happen where each party assumed the other had it.
Shared responsibility diagrams are drawn at a level of abstraction that hides the boundary. The useful exercise is naming the specific seam: who configures this, who monitors it, who is notified, who acts. It is uncomfortable because it surfaces gaps nobody wanted to own.
More on Third-party risk
- Security clauses need operational follow-throughWire the clause to something
- Supplier notification affects your response clockThey hold your start button
- Privileged vendors deserve privileged controlsSame review, very different reach
- Exit plans are security controlsThe pipe that goes back
- CI/CD secretsIt has to reach everything
- SBOMsThe list, and the verdict
