Cloud Computing Foundations · Study deck
Service Models: IaaS, PaaS, and SaaS
The previous chapter's NIST three-pillar model named "service models" as one of its three axes, with three members: Software-as-a-Service, Platform-as-a-Service, and Infrastructure-as-a-Service.
Cloud Clara is your guide for this deck.
After studying this chapter
Learning objectives
You will be able to:
- Define IaaS, PaaS, and SaaS from first principles, with named commercial examples
- Read the provider-versus-consumer responsibility bracket across Traditional, IaaS, PaaS, and SaaS
- List IaaS's essential characteristics and named challenges, and SaaS's architectural properties and limitations
- Explain: Underneath IaaS specifically, the mechanism that makes "the provider owns virtualization" possible is the hypervisor.
Major section
Who Manages What: The Responsibility Bracket
Underneath IaaS specifically, the mechanism that makes "the provider owns virtualization" possible is the hypervisor.
- The clearest way to see the difference between the three models -- and the traditional, fully self-hosted alternative they all replace part of -- is a single table naming who manages each layer of the stack.
- Provider operates; customer owns.
- A traditional physical server runs one operating system directly on hardware, with one application stack on top of that OS.
Major section
Who Manages What: The Responsibility Bracket (continued)
Clients get total control of the virtualized resources they hold, with a pre-configured allocation facility, running-status monitoring, and a usage-and-billing system that records use and calculates payment.
- SaaS moves operation of the application and its supporting data services to the provider, but it does not transfer legal ownership of customer data.
- The customer retains that ownership, decides who may use the data and for what purpose, and remains accountable for access, retention, classification, and lawful handling.
- Stored data can be retrieved at any time without failure; clients can access computational resources without failure; computation and communication are uninterrupted.
Major section
Under the Hood: PaaS Feature Stack and SaaS Multi-Tenant Architecture
No cross-platform support concerns for the customer.
- An architectural shift away from isolated, single-tenant applications: shared application components can accommodate users from multiple organizations simultaneously, transparently to all of them, while still distinguishing each tenant's own data.
- Customers use it over the internet.
- Cross-platform support required.
Major section
Summary
IaaS, PaaS, and SaaS are three points on the same trade: how much of the stack the provider runs for you, versus how much you still run yourself.
- The responsibility bracket makes that trade literal, layer by layer, with the boundary line moving from virtualization (IaaS) to the operating system and runtime (PaaS) to the entire application and data layer (SaaS).
- Underneath IaaS, a hypervisor is what lets one physical server host many isolated virtual machines.
- PaaS packages a nine-item feature bundle -- OS, scripting environment, DBMS, server software, support, storage, network access, dev tools, and hosting -- on top of that infrastructure.
Deck summary
Key takeaways
Underneath IaaS specifically, the mechanism that makes "the provider owns virtualization" possible is the hypervisor.
- Clients get total control of the virtualized resources they hold, with a pre-configured allocation facility, running-status monitoring, and a usage-and-billing system that records use and calculates payment.
- No cross-platform support concerns for the customer.
- IaaS, PaaS, and SaaS are three points on the same trade: how much of the stack the provider runs for you, versus how much you still run yourself.
Retrieval practice
Recall check 1 of 3

Cloud Clara says: answer from memory, then check your reasoning.
Q1A team wants to deploy an application they wrote without managing the operating system or server patching, but they still want to control the application's own configuration. Which service model definition matches this?
Show answer
Answer: A PaaS's defining trade is infrastructure delegated to the provider, application deployment and configuration retained by the consumer -- IaaS delegates less, SaaS delegates more.
Retrieval practice
Recall check 2 of 3

Cloud Clara says: answer from memory, then check your reasoning.
Q2In the responsibility bracket, which layer is the first one that moves from the user's column to the provider's column when going from Traditional to IaaS?
Show answer
Answer: A IaaS's boundary line sits between the operating system and virtualization: virtualization, servers, storage, and networking move to the provider; the OS and everything above it stays with the user.
Retrieval practice
Recall check 3 of 3

Cloud Clara says: answer from memory, then check your reasoning.
Q3A SaaS vendor changes its dashboard layout for every customer at once, and one customer cannot opt out or keep the old version. Which SaaS architectural property, and which limitation, does this best illustrate together?
Show answer
Answer: A The vendor chose a shared dashboard setting, so its centralized control causes this change to affect every customer; SaaS can also support tenant-specific settings.
Print reference
Answers
Answer key.
- A · PaaS's defining trade is infrastructure delegated to the provider, application deployment and configuration retained by the consumer -- IaaS delegates less, SaaS delegates more.
- A · IaaS's boundary line sits between the operating system and virtualization: virtualization, servers, storage, and networking move to the provider; the OS and everything above it stays with the user.
- A · The vendor chose a shared dashboard setting, so its centralized control causes this change to affect every customer; SaaS can also support tenant-specific settings.