Australian Government Architecture
Search

Guide to planning a cloud strategy

View more Cloud policy guidance.

On this page

About this guidance

This page supports requirement 1 of the Whole-of-government cloud computing policy: Entities to prioritise cloud when modernising IT infrastructure.

This guidance explains how to develop a cloud strategy that translates the policy requirement to prioritise cloud into clear agency direction and investment choices.

The strategy should connect cloud decisions to the agency’s Digital Investment Plan and other relevant planning and governance processes.

Who this guidance is for

This guidance is for agency staff who plan, fund, approve, deliver, operate or review cloud services. This includes:

  • Accountable executives who set direction, approve the cloud strategy, confirm investment alignment, assign accountable owners and review whether cloud decisions support agency outcomes and risk appetite.
  • Delivery and program teams who use the strategy to plan migration, sequence delivery, manage dependencies, document decisions and show how cloud options, non-cloud decisions or hybrid approaches align with policy and investment plans.
  • Operational and specialist teams who provide input on architecture, cyber security, data, procurement, finance, workforce, integration, service management, monitoring, optimisation and exit requirements.

When to use this guidance

Use this guidance when developing or refreshing a cloud strategy, assessing cloud options, sequencing migration, planning legacy retirement, or preparing evidence to show how cloud decisions align with the Cloud computing policy and agency outcomes.

Why a cloud strategy matters

Moving to the cloud is a business change, not just a technical one. It affects service delivery, risk management, capability investment, governance and cost management.

A cloud strategy supports the policy requirement to prioritise cloud computing solutions when modernising IT infrastructure.

A clear cloud strategy helps agencies decide:

  • what should move to the cloud
  • why it should move
  • when it should move
  • how data, cyber security, architecture, infrastructure, hardware and costs will be managed.

Developing a strategy

Agencies should use the following minimum contents as a practical starting point for documenting their cloud strategy.

The strategy should be proportionate to the project’s size and risk profile, and clearly show how cloud decisions support business outcomes, delivery sequencing, risk management and ongoing governance.

Suggested Cloud strategy content What agencies should document
Purpose and outcomes Scope, business outcomes, user needs and the problems the strategy is intended to solve.
Architecture and data Target architecture, integration approach, data migration, application and software migration, compute and virtual machine requirements, residency, lifecycle management and portability requirements, including plans to retire or decommission hardware no longer needed after migration.
Reusability and legacy retirement Identification of current state systems and what can be reused in conjunction with the cloud transition. Legacy systems to be retired, modernised or retained, retirement triggers, transition risks, dependencies and links to investment sequencing.
Roadmap and sequencing Migration priorities, dependencies, decision points, legacy retirement and links to the Digital Investment Plan.
Security and risk Cyber security, privacy, compliance, resilience, concentration risk and accountable risk owners.
Procurement Procurement approach, supplier model, contract considerations, market engagement, data and records obligations, and exit requirements.
Cost and value Whole-of-life cost, funding model, budgets, FinOps arrangements and optimisation review points.
Workforce capability and change Skills gaps, workforce actions, supplier knowledge transfer, change management and operating model impacts.
Governance and review Decision rights, assurance points, reporting, review cycle and evidence needed to demonstrate implementation.

Better-practice approaches

Better-practice approaches help agencies move beyond basic migration planning and make deliberate decisions about value, risk, sequencing and long-term flexibility.

Agencies should use the following checklist to test whether proposed cloud decisions support business outcomes, reduce unnecessary complexity and remain manageable over time.

Checklist item What agencies should check Better-practice action
Improve before migration Can the existing design be improved before migration? Consider whether any improvements should occur before migration, while recognising that lift and shift may be the most effective first step for some workloads. Document where later optimisation, modernisation or retirement would deliver better value.
Design for future flexibility Will the solution need to connect or move later? Design for interoperability and portability where future flexibility is important.
Embed security, privacy and risk management Have security, privacy, data protection and broader risk considerations been built into the proposed approach? Document how security, privacy and risk requirements will be addressed through strategy, design, procurement, implementation and ongoing assurance. Include accountable owners, key controls, residual risks and review points.
Align with target architecture Does the decision align with the target architecture? Align cloud choices with enterprise architecture standards, integration patterns and legacy retirement timing.
Prioritise delivery What should move first? Use a phased and prioritised approach to reduce delivery risk and build capability over time.
Test long-term value Does the option provide long-term value? Consider resilience, recovery needs, supplier dependency and whole-of-life value for money, not just upfront cost.

Related links

More cloud policy guidance

Was this information helpful?

Do not include any personal information. We are unable to respond to comments or feedback. If you would like a response, please email, or phone us. Our details are on the AGA contact page www.architecture.digital.gov.au/contact-us.