Skip to main content

IaaS Responsibility Matrix

Here is the RACI model defining the allocation of responsibilities between the client and Cloud Temple for the use of Cloud Temple's IaaS infrastructure.

Definition of the different roles

Here we recall the different RACI roles:

RoleDescription
(R) Responsible__R__esponsible for executing the process
(A) Accountable__A__ccountable for approving the process execution
(C) Consulted__C__onsulted during the process
(I) Informed__I__nformed of the process results (via tooling, the portal, or messaging)

Define your requirements

ActivityClient RoleCloud Temple Role
Define the overall architecture of your Cloud Temple platformRACI
Define the number of tenants and the number of availability zones for each tenantRACI
Define your overall disaster recovery or business continuity strategyRACI
Properly size your Cloud Temple platform (compute, storage, network, backup,...)RACI
Subscribe to services with the necessary informationRAI

Initial Implementation of Your Cloud Temple Tenants

ActivityClient RoleCloud Temple Role
Ensure the implementation of physical data centersRA
Ensure the implementation of compute infrastructureIRA
Ensure the implementation of storage infrastructureIRA
Ensure connectivity to the backbone network(1)IRA
Acquire and maintain essential software licenses for the operation of the Cloud Temple platformRA
Implement the base configuration of your Cloud Temple tenantsCIRA
Implement the initial configuration for the backup serviceCIRA
If subscribed: implement the initial network configuration for Internet and Firewall servicesCIRA
Provide the required assistance for the onboarding of your Cloud Temple environmentsIRA
Perform final configuration adjustments of the service after deliveryRAC
Configure an external authentication repository for the Cloud Temple consoleRAC
Create users for each tenant in the Cloud Temple console and assign permissionsRA
Validate the delivered platform's compliance with the SecNumCloud reference frameworkIRA
Validate the delivered platform's compliance with the required specificationsRACI

(1) The backbone network constitutes Cloud Temple's central infrastructure, providing a backbone on which specific client networks are built, and which are integrated and supported by this primary infrastructure.

Integrate your information system into your Cloud Temple environments

ActivityClient RoleCloud Temple Role
Create, install, and update your virtual machinesRA
Install and configure software and middleware on your virtual machinesRA
Purchase and hold licenses and usage rights for the operating systems of your virtual machinesRA
Configure the network for each of your virtual machinesRA
Ensure each virtual machine is associated with a consistent backup planRAC
Ensure each virtual machine is associated with a consistent disaster recovery or business continuity planRAC
Implement an antivirus protection strategy on your virtual machinesRA
Deploy a telemetry and monitoring solution on your virtual machinesRA
Define the TAG policy for your virtual machinesRA

Recurring Operations

Access and Identity Management

ActivityClient RoleCloud Temple Role
Ensure accessibility of the Cloud Temple Console service and its associated APIRA
Ensure accessibility of the information system deployed on your virtual machinesRA
Manage physical and logical access permissions for Cloud Temple teams to SecNumCloud infrastructures.RA
Administer access and the associated security policy for the Cloud Temple console interface and its APIRA
Administer access and the associated security policy for the information system hosted within your Cloud Temple tenantsRA

Operational and Security Readiness Maintenance

Activities aimed at maintaining the operational and security readiness of the infrastructure and services provided by Cloud Temple, as part of its IaaS offering, are performed to ensure compliance with the SecNumCloud qualification.

ActivityClient RoleCloud Temple Role
Ensure operational readiness of physical datacenter infrastructureIRA
Ensure security readiness of physical datacenter infrastructureIRA
Ensure operational readiness of compute infrastructureIRA
Ensure security readiness of compute infrastructure (2)RACI
Ensure operational readiness of storage infrastructureIRA
Ensure security readiness of storage infrastructureIRA
Ensure operational readiness of backbone network infrastructureIRA
Ensure security readiness of backbone network infrastructureIRA
Ensure operational readiness of virtual machines deployed in client tenants (3)RA
Ensure security readiness of virtual machines deployed in client tenants (3)RA
Ensure operational readiness of middleware deployed in client tenantsRA
Ensure security readiness of middleware deployed in client tenantsRA

(2) Cloud Temple regularly provides the latest operating system versions for your hypervisors. However, as Cloud Temple is not aware of the specifics of your production environments and the requirements associated with your workloads, the decision to proceed with updating your hypervisors' operating systems, thereby triggering a restart, rests with you. This operation can be performed via the Cloud Temple console or through the API. Professional services are available if you would like Cloud Temple to handle certain operations.

(3) Cloud Temple offers license packs for firewalls (Fortinet, Stormshield) and load balancers (HAProxy), and collaborates with your teams on the initial configuration during the implementation phase. However, the responsibility for maintaining operational and security readiness rests with you during the routine operational phase. Professional services are available if you would like Cloud Temple to handle certain operations.

Change, Incident, Problem, and Capacity Management

ActivityClient RoleCloud Temple Role
Manage incidents on physical datacenter infrastructureIRA
Manage problems on physical datacenter infrastructureRA
Manage capacity on physical datacenter infrastructureRA
Manage incidents on compute infrastructureIRA
Manage problems on compute infrastructureRA
Manage capacity on compute infrastructureRACI
Manage incidents on storage infrastructureIRA
Manage problems on storage infrastructureRA
Manage capacity on storage infrastructureRACI
Manage incidents on backbone network infrastructureIRA
Manage problems on backbone network infrastructureRA
Manage capacity on backbone network infrastructureRA
Provision a new virtual machine or create a new application environment within a client tenantRA
Modify the configuration of deployed virtual machinesRA
Delete a deployed virtual machineRA
Decide to add, modify, or remove resources on the Cloud Temple platformRACI
Execute the decision to modify resources on the Cloud Temple platformIRA
Apply tags to virtual machines in accordance with the defined policyRA

Performance Management

ActivityClient RoleCloud Temple Role
Ensure monitoring of the proper functioning and reliability of all equipment involved in delivering the SecNumCloud qualified serviceIRA
Monitor the performance of physical compute, storage, and network resources made available to your tenants (4)RIA
Supervise the performance of virtual machines supporting your environmentsRAI

(4) The Cloud Temple platform adopts a philosophy centered on providing dedicated infrastructures for compute needs (with physical blades), storage (via dedicated LUNs on SANs), and network (including firewalls and load balancers). These dedicated resources are made available to the client, and their usage and resulting load depend directly on how they are utilized. It is therefore the client's responsibility to implement and manage the necessary monitoring and metrics systems to ensure optimal operation of their information system.

Backup and Disaster Recovery Management on Integrated Backup

ActivityClient RoleCloud Temple Role
Ensure operational readiness for the backup infrastructure integrated into the Cloud Temple platform (5)RA
Ensure security readiness for the backup infrastructure integrated into the Cloud Temple platformIRA
Manage incidents for the backup infrastructure integrated into the Cloud Temple platformIRA
Manage problems for the backup infrastructure integrated into the Cloud Temple platformRA
Manage capacity for the backup infrastructure integrated into the Cloud Temple platformAIRC
Ensure operational readiness for the backup solution selected by the client within its tenants (6)RA
Ensure security readiness for the backup solution selected by the client within its tenantsRA
Manage incidents for the backup solution selected by the client within its tenantsRA
Manage problems for the backup solution selected by the client within its tenantsRA
Manage capacity for the backup solution selected by the client within its tenantsRACI
Manage the lifecycle of backup policiesRA
Ensure backup policies are consistent with the data lifecycleRA
Ensure business continuity or disaster recovery plans are consistent with the data lifecycleRA
Conduct periodic tests to evaluate the effectiveness of the backup strategyRA
Conduct periodic tests to evaluate the effectiveness of the disaster recovery or business continuity strategyRACI

(5) As of January 1, 2024, the backup solution integrated into the Cloud Temple platform is IBM Spectrum Protect Plus. This solution is fully automated and can be managed via the Cloud Temple console or the Cloud Temple API.

Backup and Disaster Recovery Management for Third-Party Platforms within a Client Tenant

ActivityClient RoleCloud Temple Role
Ensure operational readiness for the backup solution selected within the client's tenants (6)RA
Ensure security readiness for the backup solution selected within the client's tenantsRA
Manage incidents for the backup solution selected within the client's tenantsRA
Manage problems for the backup solution selected within the client's tenantsRA
Manage capacity for the backup solution selected within the client's tenantsRACI
Manage the backup policy lifecycleRA
Ensure backup policies are consistent with the data lifecycleRA
Ensure business continuity or disaster recovery plans are consistent with the data lifecycleRA
Conduct periodic tests to evaluate the effectiveness of the backup strategyRA
Conduct periodic tests to evaluate the effectiveness of the disaster recovery or business continuity strategyRACI

(6) This applies to any additional backup solution deployed in the client's environments and managed by the client. Cloud Temple offers professional services for those who wish to delegate certain operations to Cloud Temple.

Documentation and Contract Management

ActivityClient RoleCloud Temple Role
Manage the client's commercial and contractual relationship, including preparing quotes, processing orders, and managing billingIRA
Monitor the contractual follow-up of the service, including validating quotes, tracking deliveries, and monitoring billingRAI
Maintain and ensure the availability of the inventory of resources provided by Cloud Temple for the SecNumCloud offeringIRA
Maintain and provide access to the technical documentation for the SecNumCloud offeringIRA
Monitor the lifecycle of virtual machines deployed in your Cloud Temple environments via your CMDB (Configuration Management Database)RA
Keep the access policy for the Cloud Temple console interface or the Cloud Temple API up to dateRA

Log Management

ActivityClient RoleCloud Temple Role
Retain and make available the logs of the Cloud Temple IaaS platform (7)RA
Retain and make available the logs of the information system hosted within your Cloud Temple tenantsRA

(7) As of January 1, 2024, the log retention period for the platform is one year.

Client network connectivity (mpls, dedicated fiber, ipsec, ...)

ActivityClient RoleCloud Temple Role
Subscribe to operator network connectivity to access a Cloud Temple physical datacenter (8)RACI
Manage the IP addressing planRAI
Manage incidents on client operator network linksRA
Manage issues on client operator network linksRACI
Manage capacity on client operator network linksRACI

(8) Cloud Temple assumes responsibility for the network regarding its backbone infrastructure, its aggregation points as well as the datacenter interconnection points, thereby ensuring connectivity between these points and its backbone network. In the physical rack hosting offering, Cloud Temple assumes responsibility starting from the equipment located at the top of the rack, commonly referred to as "top of rack".

Reversibility

ActivityClient RoleCloud Temple Role
Plan the reversibility project and select target infrastructuresRAI
Implement transition operations, whether involving manual extraction, API usage, or any other third-party method compatible with the Cloud Temple platform.RAI
Transfer data while monitoring the impact of the migration on the service quality provided by the client's information system.RA
Proceed with dismantling Private Cloud configurations and client-associated options following contract termination.IRA
Perform secure data erasure on storage media and provide an attestationIRA