Skip to content
Foxx Cyberfoxxcyber/docs

Shared Responsibility Matrix

Domain-by-domain: what AWS provides, what Foxx Cyber implements, and what stays with you.

This is the public, domain-level view of the Bedrock Shared Responsibility Matrix (SRM) for the SaaS platform. It shows how the 14 NIST SP 800-171 domains split across the three layers of the stack.

Downloads: this table as CSV · full practice-by-practice CRM (110 practices, CSV) — both v1.0, 2026-07-29.

How to read it: AWS = inherited from the FedRAMP-authorized infrastructure. Foxx Cyber = implemented in the application or in how we configure and operate the AWS environment. You = only your organization can do it.

DomainAWSFoxx CyberYou
AC — Access ControlWireless controlsRBAC, tenant isolation, session management, least-privilege IAM, boundary controlAccount provisioning, role assignment, mobile-device and portable-storage policy
AT — Awareness & TrainingTraining for Foxx Cyber personnelTraining for your personnel
AU — Audit & AccountabilityTime sources, log infrastructureMulti-layer audit logging, log protection, monitoring, reviewReviewing your organization's in-app audit activity
CM — Configuration ManagementUnderlying platform patchingIaC, immutable containers, least functionality, change controlConfiguration of your own endpoints
IA — Identification & AuthenticationIAM primitivesUnique IDs, bcrypt storage, JWT verification, MFA capability, obscured feedbackEnabling MFA, password hygiene, credential handling in your org
IR — Incident ResponseInfrastructure-level detectionDetection stack, triage, customer notification, DFARS-aware reportingYour own IR plan, and reporting obligations for your boundary
MA — MaintenanceAll physical/hardware maintenanceControlled, MFA-gated, logged remote maintenance
MP — Media ProtectionAll physical media controls, sanitizationEncrypted backups and object storageMedia handling in your own environment
PS — Personnel SecurityAWS personnelFoxx Cyber personnel screening and offboardingYour personnel screening and offboarding
PE — Physical ProtectionAll of it (data centers)Physical protection of your own facilities/endpoints
RA — Risk AssessmentInfrastructure scanningImage scanning, continuous posture assessment, remediationRisk assessment of your own operations
CA — Security AssessmentFedRAMP assessments of AWSSSP, POA&M, continuous monitoring of the platformYour SSP and POA&M (Bedrock helps you manage them)
SC — System & Comms ProtectionNetwork infrastructure, FIPS-validated crypto modulesTLS everywhere, KMS encryption, segmentation, deny-by-default, WAFTLS-capable, patched browsers/endpoints
SI — System & Info IntegrityHypervisor/platform integrityWAF, malware-resistant design, threat detection, flaw remediationEndpoint protection on your devices

"—" means that layer has no material responsibility for the domain. Physical Protection, for example, is fully inherited from AWS for the platform — but your own offices and devices are still your responsibility under your own program.

Practices that are entirely yours

A handful of CMMC practices can't be inherited from any SaaS provider, because they govern your people and devices, not ours. Plan for these in your own program:

  • Mobile-device control and CUI encryption on mobile devices (AC.L2-3.1.18, 3.1.19)
  • Portable storage restrictions on external systems (AC.L2-3.1.21)
  • Security awareness and role-based training for your staff (AT domain)
  • Personnel screening and termination procedures for your staff (PS domain)

The Customer Responsibility Matrix page turns this into an actionable checklist.

Last updated July 29, 2026