Freeze the boundary first: provider legal entity, service and enabled features, service model, accounts or tenants, regions, workloads, data classes, agreement, customer owner, and provider chain. Then break each control into activities small enough to assign. 'Logging is shared' is too vague; separate log generation, access, export, retention, alerting, investigation, and provider-to-customer notification.
Map at least identity and privileged access, configuration, asset ownership, vulnerability handling, logging and monitoring, backup and recovery, incident handling, data protection, cryptography, changes, continuity, evidence requests, and termination. The exact technical split varies with the service. For example, ISO/IEC 27017 notes that application software belongs to the customer in typical PaaS or IaaS use, while the provider supplies it in SaaS.
For each activity, record the accountable party, performing party, agreement or service-document reference, expected evidence, frequency or event trigger, hand-off, exception route, and customer decision. If a preset provider control leaves a gap against the customer's requirements, the standard says the customer may need an additional control of its own.