View more Cloud policy guidance.
On this page
- About this guidance
- Manage security, privacy and operational risk
- Related links
- More cloud policy guidance
About this guidance
This guidance helps agencies meet requirement 3 of the Whole-of-government cloud computing policy: Entities must adopt cloud technologies responsibly and securely.
This guidance explains how agencies should identify, assign, assure and monitor cloud-specific security, privacy and operational responsibilities through normal governance processes.
Who this guidance is for
This guidance is for the people who make decisions about cloud services, deliver cloud-enabled programs, and operate or assure cloud environments. Different roles use this guidance in different ways:
- Accountable executives use this guidance to understand the risks, responsibilities and assurance evidence needed to support decisions about adopting, operating or continuing to use cloud services.
- Delivery and program teams use this guidance to build security, privacy and operational risk management into planning, procurement, design and implementation activities.
- Operational and specialist teams use this guidance to define, apply and monitor controls, manage incidents, review provider assurance and maintain evidence that risks are being managed over time.
When to use this guidance
When planning secure cloud services, agencies should:
- choose cloud providers that meet business, cyber security and operational needs
- understand and manage supply chain risks associated with external providers
- perform appropriate assurance and security assessments before adoption
- implement strong cyber security practices for cloud-hosted systems
- establish clear governance, oversight and risk management arrangements
- embed security practices across architecture, delivery and operational teams from the outset
- understand what the agency must manage and what the cloud service provider manages.
Provider certifications, assurance artefacts and shared responsibility models can support risk assessment, but they do not transfer accountability. Agencies remain responsible for understanding and managing risk.
Manage security, privacy and operational risk
Cloud security should be practical, risk-based and visible to accountable officials. Agencies should be able to show cloud-specific responsibilities that have been considered, assigned and monitored.
The Protective Security Policy Framework sets out Australian Government policy across six security domains and prescribes what Australian Government entities must do to protect their people, information and resources, both domestically and internationally. This includes requirements for non-corporate Commonwealth entities on managing the security of cloud services through:
- Mandatory Cyber Security Strategies (Section 14) and Programs (Section 15), and Technology System Authorisation (Section 13.3).
- Hosting Certification Framework (www.hostingcertification.gov.au) — The Hosting Certification Framework provides guidance to Australian Government customers enabling them to identify and source hosting services that meet enhanced privacy, sovereignty and security requirements.
- Cyber.gov.au (www.cyber.gov.au) — The Australian Cyber Security Centre sits within ASD and is the Australian Government’s technical authority on cyber security.
Related links
Cyber.gov.au has further information on areas relevant to the cybersecurity of cloud service adoption. Key topics are shown in the following table.
| Cyber.gov.au guidance | Sub-topics covered |
| Information security manual |
|
| Modern defensible architecture |
|
| Secure by Design |
|
| Mitigating cyber security incidents |
|
| Cloud computing |
|
| Managing cyber supply chains |
|
| Artificial intelligence |
|
These areas should be treated as part of normal governance and assurance, not as one-off technical tasks. Decision-makers need visibility of which controls are in place, who owns them, what residual risks have been accepted and how control effectiveness will be reviewed over time.
Provider certifications, assurance artefacts and shared responsibility models can support risk assessment, but they do not transfer accountability. Agencies remain responsible for understanding and managing risk.
More cloud policy guidance
- Guide to meeting the requirements of the Whole-of-government cloud computing policy
- Guide to planning a cloud strategy
- Guide to cloud migration and legacy retirement
- Guide to procuring cloud services
- Guide to managing cloud provider lock-in, portability and exit planning
- Guide to reviewing and continuously improving cloud adoption
- Guide to managing cloud and usage costs, including AI costs
- Guide to developing cloud capability in your agency