Cloud computing provides on-demand access to a shared pool of configurable computing resources. NIST describes essential characteristics including on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. These characteristics do not make a workload automatically cheaper, safer, scalable, or resilient.

Service models change responsibility

ModelCustomer generally managesProvider generally manages
IaaSGuest OS, applications, identities, data, network configurationPhysical facilities, hardware and virtualization layer
PaaSApplication, identities, data and service configurationMore of the runtime, platform and infrastructure
SaaSUsers, data, configuration, integrations and acceptable useApplication service and underlying platform

Exact boundaries are contractual and service-specific. Verify current provider documentation, architecture, support, and audit evidence.

Deployment is not binary

Public, private, community, hybrid, sovereign, edge, and multi-cloud designs address different latency, control, residency, dependency, and operating needs. More clouds can add portability options but also increase identity, networking, observability, skills, and consistency burden.

Evaluate a workload

  1. Define users, data classification, regions, latency, availability, recovery, throughput, and compliance.
  2. Map identities, networks, encryption, secrets, logging, backups, dependencies, and administrative paths.
  3. Model total cost: compute, storage, requests, egress, licenses, support, observability, engineering, idle capacity, migration, and exit.
  4. Test scaling, quota exhaustion, zone/region failure, dependency outage, restore, key rotation, incident response, and provider exit.
  5. Record accepted risks and accountable owners.

Use cloud strategy, architecture patterns, data-access governance, and migration guidance.

Operate continuously

Apply least privilege, strong authentication, network segmentation, secure configuration, vulnerability management, data governance, immutable/auditable logs, monitoring, budget alerts, tested backup/restore, incident response, and change control. Provider availability does not replace application-level resilience.

Historical article substantially updated September 4, 2026. Original publication date preserved.