Shared Responsibility Matrix
Domain-by-domain: what AWS provides, what Foxx Cyber implements, and what stays with you.
This is the public, domain-level view of the Bedrock Shared Responsibility Matrix (SRM) for the SaaS platform. It shows how the 14 NIST SP 800-171 domains split across the three layers of the stack.
Downloads: this table as CSV · full practice-by-practice CRM (110 practices, CSV) — both v1.0, 2026-07-29.
How to read it: AWS = inherited from the FedRAMP-authorized infrastructure. Foxx Cyber = implemented in the application or in how we configure and operate the AWS environment. You = only your organization can do it.
| Domain | AWS | Foxx Cyber | You |
|---|---|---|---|
| AC — Access Control | Wireless controls | RBAC, tenant isolation, session management, least-privilege IAM, boundary control | Account provisioning, role assignment, mobile-device and portable-storage policy |
| AT — Awareness & Training | — | Training for Foxx Cyber personnel | Training for your personnel |
| AU — Audit & Accountability | Time sources, log infrastructure | Multi-layer audit logging, log protection, monitoring, review | Reviewing your organization's in-app audit activity |
| CM — Configuration Management | Underlying platform patching | IaC, immutable containers, least functionality, change control | Configuration of your own endpoints |
| IA — Identification & Authentication | IAM primitives | Unique IDs, bcrypt storage, JWT verification, MFA capability, obscured feedback | Enabling MFA, password hygiene, credential handling in your org |
| IR — Incident Response | Infrastructure-level detection | Detection stack, triage, customer notification, DFARS-aware reporting | Your own IR plan, and reporting obligations for your boundary |
| MA — Maintenance | All physical/hardware maintenance | Controlled, MFA-gated, logged remote maintenance | — |
| MP — Media Protection | All physical media controls, sanitization | Encrypted backups and object storage | Media handling in your own environment |
| PS — Personnel Security | AWS personnel | Foxx Cyber personnel screening and offboarding | Your personnel screening and offboarding |
| PE — Physical Protection | All of it (data centers) | — | Physical protection of your own facilities/endpoints |
| RA — Risk Assessment | Infrastructure scanning | Image scanning, continuous posture assessment, remediation | Risk assessment of your own operations |
| CA — Security Assessment | FedRAMP assessments of AWS | SSP, POA&M, continuous monitoring of the platform | Your SSP and POA&M (Bedrock helps you manage them) |
| SC — System & Comms Protection | Network infrastructure, FIPS-validated crypto modules | TLS everywhere, KMS encryption, segmentation, deny-by-default, WAF | TLS-capable, patched browsers/endpoints |
| SI — System & Info Integrity | Hypervisor/platform integrity | WAF, malware-resistant design, threat detection, flaw remediation | Endpoint protection on your devices |
"—" means that layer has no material responsibility for the domain. Physical Protection, for example, is fully inherited from AWS for the platform — but your own offices and devices are still your responsibility under your own program.
Practices that are entirely yours
A handful of CMMC practices can't be inherited from any SaaS provider, because they govern your people and devices, not ours. Plan for these in your own program:
- Mobile-device control and CUI encryption on mobile devices (AC.L2-3.1.18, 3.1.19)
- Portable storage restrictions on external systems (AC.L2-3.1.21)
- Security awareness and role-based training for your staff (AT domain)
- Personnel screening and termination procedures for your staff (PS domain)
The Customer Responsibility Matrix page turns this into an actionable checklist.