Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Security in Yandex Cloud
  • Key security features
  • Division of responsibility for security
  • Compliance
  • Security measures on the Yandex Cloud side
  • Security tools available to cloud service users
  • User support policy during vulnerability scanning
  • Security bulletins
  • Public IP address ranges

In this article:

  • Private infrastructure
  • IaaS
  • PaaS
  • SaaS

Division of responsibility for security

Written by
Yandex Cloud
Updated at April 16, 2025
View in Markdown
  • Private infrastructure
  • IaaS
  • PaaS
  • SaaS

The security of systems dependent on cloud services involves a division of responsibility between the customer (end system owner) and the provider (cloud infrastructure owner). The division of this responsibility depends on the model of cloud services: IaaS (Infrastructure as a Service), PaaS (Platform as a Service), or SaaS (Software as a Service).

It can be visualized in a table, where:

  • Client
  • Yandex Cloud
Private
infrastructure
IaaS PaaS SaaS
Data access management
Application security
OS security
Network security (Overlay)
Backups
Encryption
Audit logs
Data storage and hardware security
Network security (Underlay)
Physical security and disaster recovery

In any of the four situations, only the client is responsible for controlling access and managing permissions. Other areas of responsibility depend on the model.

Private infrastructurePrivate infrastructure

The client is solely responsible for ensuring security at all levels.

IaaSIaaS

The provider is responsible for the physical security and fault tolerance of the platform itself, network security, the collection and analysis of security events from hypervisors and other infrastructure components.

The client is to back up VMs, protect the virtual network, ensure the security of guest OS, control access, and secure cloud user accounts.

PaaSPaaS

The provider is responsible for the security of the higher-level layers of the infrastructure. This includes VM protection and DB backups.

The client handles data classification, controls access to data, configures processes to protect data, and takes responsibility for controlling user access and interaction with third-party services.

SaaSSaaS

The provider is responsible for most security aspects: data accessibility and integrity, monitoring and logging, physical security, and security for the network, service components, and the application itself.

The client is responsible for managing user access to data.

Was the article helpful?

Previous
Key security features
Next
Compliance
© 2026 Direct Cursus Technology L.L.C.