---
name: framework-financial-services-shared-responsibilities
title: Responsibilities for operating services in your deployment
description: In IBM Cloud, the responsibilities for deploying, operating, and securing products are shared between IBM and you, the application provider. It is important for you to understand these responsibilities for every IBM Cloud service you've deployed as part of the reference architectures.
last-updated: 2024-11-19
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Responsibilities for operating services in your deployment
{: #shared-responsibilities}

In IBM Cloud, the responsibilities for deploying, operating, and securing products are shared between IBM and you, the application provider. It is important for you to understand these responsibilities for every IBM Cloud service you've deployed as part of the reference architectures.
{: shortdesc}

Depending on the product, the responsibility for the following types of tasks (which span activities for Day 0, Day 1, and Day 2) can be exclusive to IBM, you, or shared. The tasks for each type of product are grouped in the following categories, which cut across nearly all of the IBM Cloud Framework for Financial Services's [best practices and requirements](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-best-practices&format=markdown).

Incident and operations management
:   Includes tasks such as monitoring, event management, high availability, problem determination, recovery, and full state backup and recovery.

Change management
:   Includes tasks such as deployment, configuration, upgrades, patching, configuration changes, and deletion.

Identity and access management
:   Includes tasks such as authentication, authorization, access control policies, and approving, granting, and revoking access.

Security and regulation compliance
:   Includes tasks such as security controls implementation and compliance certification.

Disaster recovery
:   Includes tasks such as providing dependencies on disaster recovery sites, provision disaster recovery environments, data and configuration backup, replicating data and configuration to the disaster recovery environment, and failover on disaster events.

For more information, see [Shared responsibilities for using IBM Cloud products](https://cloud.ibm.com/docs/overview/terms-of-use?topic=overview-shared-responsibilities&format=markdown).

## Responsibilities for Financial Services Validated services
{: #related-resources}

The following table provides references that describe your responsibilities for each Financial Services Validated service in the reference architecture.

| Category | VPC reference architecture | Satellite reference architecture | Optional for both |
|----------|-------------------|-------------------|-------------------|
| Core  | - [VPC infrastructure services](https://cloud.ibm.com/docs/vpc?topic=vpc-responsibilities-vpc&format=markdown) [^tabletext] | - [Satellite](https://cloud.ibm.com/docs/satellite?topic=satellite-responsibilities&format=markdown) |  |
| Containers  | - [Red Hat OpenShift on IBM Cloud](https://cloud.ibm.com/docs/openshift?topic=openshift-responsibilities_iks&format=markdown) \n - Container Registry [^tabletext-no-specific-link-container-registry] | - [Red Hat OpenShift on IBM Cloud](https://cloud.ibm.com/docs/openshift?topic=openshift-satellite-responsibilities&format=markdown) [^tabletext-satellite-enabled-openshift] \n - Container Registry |  |
| Networking | - [VPC infrastructure services](https://cloud.ibm.com/docs/vpc?topic=vpc-responsibilities-vpc&format=markdown) \n - [Direct Link](https://cloud.ibm.com/docs/dl?topic=dl-dl-responsibilities&format=markdown) \n - [Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-tg-responsibilities&format=markdown) | | |
| Storage  | - [Block Storage for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-responsibilities-vpc&format=markdown) \n - [Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-responsibilities&format=markdown) | - [Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-responsibilities&format=markdown) |  |
| Security  | - [Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown) | - [Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown) | - App ID [^tabletext-no-specific-link-appid] |
| Logging and monitoring  | - [Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?topic=atracker-shared-responsibilities&format=markdown) \n - Compliance Manager \n - [Flow Logs for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-responsibilities-vpc&format=markdown)  | - [Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?topic=atracker-shared-responsibilities&format=markdown) \n - Compliance Manager |  |
| Integration  | |  | - [Event Streams](https://cloud.ibm.com/docs/EventStreams?topic=EventStreams-event_streams_responsibilities&format=markdown) |
{: caption="Your responsibilities for IBM Cloud services in the reference architectures" caption-side="top"}

[^tabletext]: Only required if enabling public internet access to workload VPC for application consumers.

[^tabletext-satellite-enabled-openshift]: {{site.data.content.satellite-enabled-openshift}}

[^tabletext-no-specific-link-appid]: There is not a specific shared responsibility article for App ID.

[^tabletext-no-specific-link-container-registry]: There is not a specific shared responsibility article for Container Registry.