Cloud computing provides on-demand access to a shared pool of configurable computing resources. NIST describes essential characteristics including on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. These characteristics do not make a workload automatically cheaper, safer, scalable, or resilient.
Service models change responsibility
| Model | Customer generally manages | Provider generally manages |
|---|---|---|
| IaaS | Guest OS, applications, identities, data, network configuration | Physical facilities, hardware and virtualization layer |
| PaaS | Application, identities, data and service configuration | More of the runtime, platform and infrastructure |
| SaaS | Users, data, configuration, integrations and acceptable use | Application service and underlying platform |
Exact boundaries are contractual and service-specific. Verify current provider documentation, architecture, support, and audit evidence.
Deployment is not binary
Public, private, community, hybrid, sovereign, edge, and multi-cloud designs address different latency, control, residency, dependency, and operating needs. More clouds can add portability options but also increase identity, networking, observability, skills, and consistency burden.
Evaluate a workload
- Define users, data classification, regions, latency, availability, recovery, throughput, and compliance.
- Map identities, networks, encryption, secrets, logging, backups, dependencies, and administrative paths.
- Model total cost: compute, storage, requests, egress, licenses, support, observability, engineering, idle capacity, migration, and exit.
- Test scaling, quota exhaustion, zone/region failure, dependency outage, restore, key rotation, incident response, and provider exit.
- Record accepted risks and accountable owners.
Use cloud strategy, architecture patterns, data-access governance, and migration guidance.
Operate continuously
Apply least privilege, strong authentication, network segmentation, secure configuration, vulnerability management, data governance, immutable/auditable logs, monitoring, budget alerts, tested backup/restore, incident response, and change control. Provider availability does not replace application-level resilience.
Historical article substantially updated September 4, 2026. Original publication date preserved.

Historical comments from Datanizant
No public comments on this article
No approved public comments were included in the WordPress export for this article.