2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
Chapter 1: Systems & Data GovernanceLesson 1.1

1.1 Enterprise IT Architecture: Cloud Shared Responsibility & ERP Systems

Examine modern enterprise technology architectures, contrasting on-premises infrastructures with IaaS, PaaS, and SaaS cloud models under the Shared Responsibility Model, and analyzing the internal control benefits of centralized ERP databases.

🎯 Essential Technical Takeaways

  • Under the IaaS Shared Responsibility Model, the cloud provider secures the physical facility and hypervisor; the customer secures guest OS, applications, firewalls, and data.
  • In SaaS, the vendor manages the entire stack; the customer is responsible solely for user access management and data classification.
  • Hybrid clouds combine public cloud agility with private data residency, but introduce latency and multi-environment policy complexity.
  • Centralized ERP systems enforce single-point data entry and eliminate batch reconciliation errors across operational silos.

Modern enterprise accounting systems rely heavily on distributed and cloud-enabled architectures. Under NIST SP 800-145 and AICPA SOC reporting guidance, organizations evaluating cloud environments must understand the Shared Responsibility Model. In Infrastructure as a Service (IaaS), the cloud service provider (CSP) manages only the physical data center, physical servers, and hypervisor virtualization layer. The enterprise customer retains full operational and security responsibility for configuring operating systems, applying security patches, configuring virtual firewalls, managing databases, and enforcing access controls.

In Platform as a Service (PaaS), the provider manages the physical infrastructure, hypervisor, operating system, and database management runtime, leaving the customer responsible for application code and data. In Software as a Service (SaaS), the provider manages the entire software and hardware stack; the enterprise customer manages only user identities, access permissions, and data governance.

Enterprise Resource Planning (ERP) platforms integrate formerly siloed departmental applications (sales, inventory, manufacturing, payroll) into a single unified relational database. This architectural centralization provides immense internal control advantages: single-point data entry eliminates duplicate input, automated business rules enforce validation across modules, and general ledger postings occur in real time without batch synchronization failures.

⚠️ CPA Evolution Exam Traps & Control Pitfalls

  • Assuming the cloud service provider manages OS patches or data backups in an IaaS deployment.
  • Believing cloud adoption eliminates the need for enterprise IT General Controls (ITGCs).
  • Confusing public cloud multi-tenancy with hybrid cloud architecture.

Interactive Knowledge Checkpoint

Knowledge Checkpoint • Section 1.1

An enterprise migrates its customer billing application from an on-premises data center to an Infrastructure as a Service (IaaS) cloud provider. The company's IT audit committee requests clarification regarding which security and control layers remain the direct responsibility of the enterprise versus the cloud service provider (CSP). Under the standard cloud shared responsibility model, which of the following is solely the responsibility of the enterprise in an IaaS deployment?