Skip to content

Infrastructure responsibility matrix

Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.

  • Project / nonsensitive identifier: [fill in]
  • Prepared by / accountable owner: [fill in]
  • Version / date / next review: [fill in]
  • Classification and agreement references: [fill in]
  • Approved evidence location: [fill in]

Name accountable parties

  • CyVerse service contact: [fill in]
  • VM/cloud operator: [fill in]
  • Institutional security/compliance approver: [fill in]
  • Research team implementation owner: [fill in]
  • Data custodian: [fill in]

Negotiate responsibilities; this is not a provider commitment

Control CyVerse scope VM/cloud scope Institution scope Team scope Custodian scope Accountable person Evidence / handoff / unresolved
Authentication / MFA
Encryption / keys
Storage / recovery
Compute / admin access
Network / transfer
Auditing / monitoring
Incident response
Retention / destruction
Output disclosure
  • Cross-provider escalation and incident coordination: [fill in]
  • Unassigned controls and approval blockers: [fill in]
  • Confirmation of commitments from each party: [fill in]

Review and authorization

  • Unresolved controls / remediation owner / due date: [fill in]
  • Exceptions, approving authority, scope, and expiry: [fill in]
  • Custodian decision / date / evidence reference: [fill in]
  • Institutional decision / date / evidence reference: [fill in]
  • Provider confirmation references: [fill in]
  • Material changes requiring revalidation: [fill in]

For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.