Who is responsible to secure configuration files from unauthorized users

ASP.NET configures IIS to deny access to any user that requests access to the Machine.config or Web.config files.