Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Shared Responsibility Model

Security, governance and compliance in FRIDGE is a shared responsibility between the TRE Operator Organisation and theFRIDGE Hosting Organisation. The Resource Allocator also plays a more minor role in judging the suitability of a project. A summary of the distribution of responsibilities, and their relation to the 5 Safes is shown in Figure 1

A diagram showing the FRIDGE Shared Responsibility Model, organised into three horizontal layers mapped against the Five Safes framework. The Resource Allocator layer at the top covers Project Suitability and Workspace Resource Allocation, corresponding to Safe Projects. The TRE Provider Organisation layer in the middle covers Study Membership (Safe Projects), Safe Researcher Accreditation (Safe People), Data Lifecycle Management (Safe Data), Output Management (Safe Outputs), and a Safe Setting group comprising TRE Platform, TRE Code, Applications, Identity and Access Management, Client Side Encryption, and Network Traffic Protection. The FRIDGE Hosting Organisation layer at the bottom covers Tenancy Isolation, Kubernetes Clusters, Public IP Addressing, and Physical Hardware and Network, also mapped to Safe Setting.

Figure 1:A high-level view of the responsibilities shared between the three key organisations. Each responsibility is mapped to one of the 5 Safes.

This shared model helps to distribute operational burden appropriately across parties:

Organisations should carefully consider their role within this model, as responsibilities vary depending on how FRIDGE services are integrated into existing TRE operations and the applicable legal, regulatory and data governance frameworks in place.

Shared Processes

While the shared responsibility model clearly delineates ownership, operating safely in practice requires a set of agreed cross-boundary processes. Responsibility for a control does not eliminate the need for coordination with other parties in exercising it. Such shared processes are described in FRIDGE Lifecycle and Data Flow.