Cloud services can improve access, collaboration, automation, and scalability, but those outcomes are not automatic. A migration can also reproduce weak processes, broaden permissions, create surprise costs, and concentrate dependencies. Productivity improves when the operating model changes with the technology.
Current as of 2026-08-15
NIST SP 800-145 defines cloud computing through five essential characteristics, three service models, and four deployment models. CISA’s Cloud Security Technical Reference Architecture hub discusses shared services, migration, and cloud security posture management.
Decision summary
- Choose cloud services for a defined workflow and measurable constraint.
- Assign service, information, identity, cost, security, and recovery ownership.
- Standardize configuration and permissions before scaling.
- Measure adoption, outcome, risk, cost, and exit readiness.
Define the workload decision
Document users, locations, information classes, transaction volumes, latency, integrations, availability, recovery, support, legal or contractual constraints, and current cost. Compare rehost, replatform, replace, retain, and retire options. A cloud label does not decide the right architecture.
Design the operating baseline
- Named service and information owners.
- Federated identity, MFA, least privilege, and privileged administration.
- Approved regions, encryption, logging, configuration, and network patterns.
- Backup and restoration responsibility.
- Vendor, subprocessor, support, portability, and exit terms.
- Tagging, budgets, alerts, rightsizing, and lifecycle controls.
Pilot the real workflow
Test representative data, permissions, devices, integrations, accessibility, support, failure modes, and recovery. Include users who perform the work and measure the complete transaction, not feature activation. Capture training needs, manual steps, oversharing, performance, and cost before broad rollout.
Operate for sustained value
Review orphaned resources, excess privilege, configuration drift, spend anomalies, backup evidence, vendor changes, and capacity. Track time saved or quality improved against a baseline while accounting for support and governance overhead. Maintain exports, architecture records, and an exit test proportionate to concentration risk.
Next step for your environment
Choose one cloud-enabled workflow and document its owner, baseline, target outcome, security controls, total cost, recovery path, and exit option.
Record the accountable owner, baseline, source date, decision, exceptions, acceptance evidence, and review trigger. Test consequential changes in a bounded environment, maintain a rollback path, and verify the real result before closing the work. Product names, availability, pricing, legal requirements, and security guidance can change; recheck the primary sources whenever the decision is renewed or the environment changes.
If you need an independent baseline before changing production systems, start with an ITECS technology and security assessment and keep the resulting evidence with the decision record.
Sources and update trigger
- NIST — SP 800-145: Definition of Cloud Computing
- CISA — Cloud Security Technical Reference Architecture hub
Review trigger: Review after workload, identity, vendor, region, price, contract, recovery, architecture, or business-outcome changes.
