Infrastructure responsibility matrix¶
Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.
- Project / nonsensitive identifier: [fill in]
- Prepared by / accountable owner: [fill in]
- Version / date / next review: [fill in]
- Classification and agreement references: [fill in]
- Approved evidence location: [fill in]
Name accountable parties¶
- CyVerse service contact: [fill in]
- VM/cloud operator: [fill in]
- Institutional security/compliance approver: [fill in]
- Research team implementation owner: [fill in]
- Data custodian: [fill in]
Negotiate responsibilities; this is not a provider commitment¶
| Control | CyVerse scope | VM/cloud scope | Institution scope | Team scope | Custodian scope | Accountable person | Evidence / handoff / unresolved |
|---|---|---|---|---|---|---|---|
| Authentication / MFA | |||||||
| Encryption / keys | |||||||
| Storage / recovery | |||||||
| Compute / admin access | |||||||
| Network / transfer | |||||||
| Auditing / monitoring | |||||||
| Incident response | |||||||
| Retention / destruction | |||||||
| Output disclosure |
- Cross-provider escalation and incident coordination: [fill in]
- Unassigned controls and approval blockers: [fill in]
- Confirmation of commitments from each party: [fill in]
Review and authorization¶
- Unresolved controls / remediation owner / due date: [fill in]
- Exceptions, approving authority, scope, and expiry: [fill in]
- Custodian decision / date / evidence reference: [fill in]
- Institutional decision / date / evidence reference: [fill in]
- Provider confirmation references: [fill in]
- Material changes requiring revalidation: [fill in]
For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.