View more Cloud policy guidance.
On this page
- About this guidance
- Why cloud matters for government
- How this guidance supports the Cloud computing policy
- When to use this guidance
- What agencies must be able to demonstrate
- Justification of hosting solutions
- More cloud policy guidance
About this guidance
This guidance assists agencies in meeting the requirements of the Whole-of-government cloud computing policy.
Guidance does not replace what is stated in the policy. The cloud policy’s requirements take precedence over guidance in the event of any differences in content or interpretation.
Why cloud matters for government
Cloud computing supports the modernisation of government ICT infrastructure and provides secure, scalable capability that can improve service delivery, strengthen resilience and enable innovation, including using artificial intelligence. It also helps agencies reduce the risks associated with legacy systems and respond more effectively to changing technology and service needs.
The Cloud computing policy prioritises cloud adoption for new digital and ICT initiatives and upgrades, while recognising agencies must assess solutions against their requirements and use cases.
As part of a cloud transition strategy, agencies need to assess how to develop interoperable and portable solutions and identify what existing technologies and capabilities can be reused, including opportunities to decommission legacy systems.
Agencies must also manage cloud adoption responsibly by addressing security, privacy, performance, cost and workforce capability considerations, and by maintaining exit and data migration plans.
How this guidance supports the Cloud computing policy
This guidance translates the Cloud computing policy across the cloud into practical direction agencies.
It helps agencies:
- make risk-informed, outcome-focused cloud decisions
- coordinate business, technical, security, commercial, financial and workforce considerations
- manage cloud services responsibly, including cost, resilience, accountability and value for money.
Agencies should apply the guidance proportionately to their operating context, risks and service needs.
When to use this guidance
Use this guidance at key decision points across the cloud lifecycle, including strategy and investment planning, approvals, procurement, delivery, operation, assurance and review.
Apply it early enough to shape architecture, security, cost, capability and exit decisions, particularly when assessing cloud options or justifying a hybrid or non-cloud approach.
It is also useful when reviewing existing services, supplier arrangements, legacy retirement plans or opportunities for improvement.
What agencies must be able to demonstrate
Agencies should be able to provide evidence of how they are following the Cloud computing policy and explain how cloud decisions are made, including who is accountable for those decisions.
Cloud adoption is not only an ICT responsibility. Good outcomes depend on coordinated business, technical, cyber security, commercial, financial and workforce decisions.
The table below sets out key governance roles and accountabilities that support responsible and accountable cloud adoption.
| Role | Accountability |
| Accountable executives | Set direction, approve the cloud strategy, assign accountable owners, accept or escalate material risks, and oversee whether cloud adoption supports agency outcomes, value for money, cost management and capability. |
| Delivery and program teams | Plan and deliver cloud adoption activities, including roadmaps, migration sequencing, dependency management, procurement, architecture, finance, change management and decision records. |
| Operational and specialist teams | Operate, monitor and improve cloud services by managing controls, identity, logging, security monitoring, cost optimisation, service performance, supplier dependencies and continuous improvement. |
Justification of hosting solutions
Requirement 1 of the Cloud computing policy states entities must 'Adopt cloud solutions for all new digital and ICT initiatives and upgrades unless an alternative is justified.'
The Cloud computing policy acknowledges there are different variants of cloud solutions. Additionally, hybrid cloud solutions sometimes best leverage the benefits of cloud while potentially meeting some other business needs most effectively.
Irrespective of the solution chosen, entities must be able to demonstrate how it achieves the outcomes stated in the policy, including scalability, security, interoperability and portability.
Non-cloud solutions, including on-premises mainframes, should only be proposed in exceptional circumstances. Agencies proposing these solutions must clearly demonstrate that:
- a cloud solution is not feasible
- the hosting strategy minimises lock-in and incorporates future-proofing measures as much as possible - including opportunities to leverage cloud and its associated benefits in the future
- the hosting strategy identifies opportunities to decommission other legacy technology.
More cloud policy guidance
Following is a list of guidance resources, ordered approximately by implementation journey but noting these stages overlap considerably. The most applicable policy requirements are also listed on each page.
- Guide to planning a cloud strategy
- Guide to cloud migration and legacy retirement
- Guide to procuring cloud services
- Guide to managing cloud provider lock-in, portability and exit planning
- Guide to managing security, privacy and operational risk
- Guide to reviewing and continuously improving cloud adoption
- Guide to managing cloud and usage costs, including AI costs
- Guide to developing cloud capability in your agency