Who exactly determines where the security obligations of a cloud provider end and the duties of the customer begin? Furthermore, this framework defines that the provider manages security of the cloud while the customer remains responsible for security in the cloud. How do you ensure your team effectively manages its portion of this critical safety partnership?