Australian Government Architecture
Search

Guide to meeting the requirements of the Whole-of-government cloud computing policy

View more Cloud policy guidance.

On this page

About this guidance

This guidance assists agencies in meeting the requirements of the Whole-of-government cloud computing policy.

Guidance does not replace what is stated in the policy. The cloud policy’s requirements take precedence over guidance in the event of any differences in content or interpretation.

Why cloud matters for government

Cloud computing supports the modernisation of government ICT infrastructure and provides secure, scalable capability that can improve service delivery, strengthen resilience and enable innovation, including using artificial intelligence. It also helps agencies reduce the risks associated with legacy systems and respond more effectively to changing technology and service needs.

The Cloud computing policy prioritises cloud adoption for new digital and ICT initiatives and upgrades, while recognising agencies must assess solutions against their requirements and use cases.

As part of a cloud transition strategy, agencies need to assess how to develop interoperable and portable solutions and identify what existing technologies and capabilities can be reused, including opportunities to decommission legacy systems.

Agencies must also manage cloud adoption responsibly by addressing security, privacy, performance, cost and workforce capability considerations, and by maintaining exit and data migration plans.

How this guidance supports the Cloud computing policy

This guidance translates the Cloud computing policy across the cloud into practical direction agencies.

It helps agencies:

  • make risk-informed, outcome-focused cloud decisions
  • coordinate business, technical, security, commercial, financial and workforce considerations
  • manage cloud services responsibly, including cost, resilience, accountability and value for money.

Agencies should apply the guidance proportionately to their operating context, risks and service needs.

When to use this guidance

Use this guidance at key decision points across the cloud lifecycle, including strategy and investment planning, approvals, procurement, delivery, operation, assurance and review.

Apply it early enough to shape architecture, security, cost, capability and exit decisions, particularly when assessing cloud options or justifying a hybrid or non-cloud approach.

It is also useful when reviewing existing services, supplier arrangements, legacy retirement plans or opportunities for improvement.

What agencies must be able to demonstrate

Agencies should be able to provide evidence of how they are following the Cloud computing policy and explain how cloud decisions are made, including who is accountable for those decisions.

Cloud adoption is not only an ICT responsibility. Good outcomes depend on coordinated business, technical, cyber security, commercial, financial and workforce decisions.

The table below sets out key governance roles and accountabilities that support responsible and accountable cloud adoption.

Role Accountability
Accountable executives Set direction, approve the cloud strategy, assign accountable owners, accept or escalate material risks, and oversee whether cloud adoption supports agency outcomes, value for money, cost management and capability.
Delivery and program teams Plan and deliver cloud adoption activities, including roadmaps, migration sequencing, dependency management, procurement, architecture, finance, change management and decision records.
Operational and specialist teams Operate, monitor and improve cloud services by managing controls, identity, logging, security monitoring, cost optimisation, service performance, supplier dependencies and continuous improvement.

Justification of hosting solutions

Requirement 1 of the Cloud computing policy states entities must 'Adopt cloud solutions for all new digital and ICT initiatives and upgrades unless an alternative is justified.'

The Cloud computing policy acknowledges there are different variants of cloud solutions. Additionally, hybrid cloud solutions sometimes best leverage the benefits of cloud while potentially meeting some other business needs most effectively.

Irrespective of the solution chosen, entities must be able to demonstrate how it achieves the outcomes stated in the policy, including scalability, security, interoperability and portability.

Non-cloud solutions, including on-premises mainframes, should only be proposed in exceptional circumstances. Agencies proposing these solutions must clearly demonstrate that:

  • a cloud solution is not feasible
  • the hosting strategy minimises lock-in and incorporates future-proofing measures as much as possible - including opportunities to leverage cloud and its associated benefits in the future
  • the hosting strategy identifies opportunities to decommission other legacy technology.

More cloud policy guidance

Following is a list of guidance resources, ordered approximately by implementation journey but noting these stages overlap considerably. The most applicable policy requirements are also listed on each page.

Was this information helpful?

Do not include any personal information. We are unable to respond to comments or feedback. If you would like a response, please email, or phone us. Our details are on the AGA contact page www.architecture.digital.gov.au/contact-us.