Australian Government Architecture
Search

Guide to managing security, privacy and operational risk

View more Cloud policy guidance.

On this page

About this guidance

This guidance helps agencies meet requirement 3 of the Whole-of-government cloud computing policy: Entities must adopt cloud technologies responsibly and securely.

This guidance explains how agencies should identify, assign, assure and monitor cloud-specific security, privacy and operational responsibilities through normal governance processes.

Who this guidance is for

This guidance is for the people who make decisions about cloud services, deliver cloud-enabled programs, and operate or assure cloud environments. Different roles use this guidance in different ways:

  • Accountable executives use this guidance to understand the risks, responsibilities and assurance evidence needed to support decisions about adopting, operating or continuing to use cloud services.
  • Delivery and program teams use this guidance to build security, privacy and operational risk management into planning, procurement, design and implementation activities.
  • Operational and specialist teams use this guidance to define, apply and monitor controls, manage incidents, review provider assurance and maintain evidence that risks are being managed over time.

When to use this guidance

When planning secure cloud services, agencies should:

  • choose cloud providers that meet business, cyber security and operational needs
  • understand and manage supply chain risks associated with external providers
  • perform appropriate assurance and security assessments before adoption
  • implement strong cyber security practices for cloud-hosted systems
  • establish clear governance, oversight and risk management arrangements
  • embed security practices across architecture, delivery and operational teams from the outset
  • understand what the agency must manage and what the cloud service provider manages.

Provider certifications, assurance artefacts and shared responsibility models can support risk assessment, but they do not transfer accountability. Agencies remain responsible for understanding and managing risk.

Manage security, privacy and operational risk

Cloud security should be practical, risk-based and visible to accountable officials. Agencies should be able to show cloud-specific responsibilities that have been considered, assigned and monitored.

The Protective Security Policy Framework sets out Australian Government policy across six security domains and prescribes what Australian Government entities must do to protect their people, information and resources, both domestically and internationally. This includes requirements for non-corporate Commonwealth entities on managing the security of cloud services through:

  • Mandatory Cyber Security Strategies (Section 14) and Programs (Section 15), and Technology System Authorisation (Section 13.3).
  • Hosting Certification Framework (www.hostingcertification.gov.au) — The Hosting Certification Framework provides guidance to Australian Government customers enabling them to identify and source hosting services that meet enhanced privacy, sovereignty and security requirements.
  • Cyber.gov.au (www.cyber.gov.au) — The Australian Cyber Security Centre sits within ASD and is the Australian Government’s technical authority on cyber security.

Related links

Cyber.gov.au has further information on areas relevant to the cybersecurity of cloud service adoption. Key topics are shown in the following table.

Cyber.gov.au guidance Sub-topics covered
Information security manual
  • Cyber security principles
  • Cyber security guidelines
  • Cyber security terminology
  • Cloud controls matrix
Modern defensible architecture
  • Centrally managed enterprise identities
  • High confidence authentication
  • Contextual authorisation
  • Reliable asset inventory
  • Secure endpoints
  • Reduced attack surface
  • Resilient networks
  • Secure-by-Design
  • Comprehensive validation and assurance
  • Continuous and actionable monitoring
Secure by Design
  • Holistic secure organization
  • Early and sustained security
  • Secure product development
  • Testing
  • Continuous assurance
  • Secure deprecation
Mitigating cyber security incidents
  • Strategies to mitigate cyber security incidents
Cloud computing
  • Blueprint for Secure Cloud
  • Cloud assessment and authorization
  • Cloud computing security for cloud service providers
  • Cloud computing security for tenants
  • Cloud shared responsibility model
Managing cyber supply chains
  • Cyber supply chain risk management
  • Choosing secure and verifiable technologies
  • Identifying cyber supply chain risks
  • Managed service providers
  • Artificial intelligence and machine learning: Supply chain risks and mitigations
Artificial intelligence
  • Deploying AI systems securely
  • Agentic AI services
  • AI data security
  • Secure AI systems development
  • Opportunities for AI in cyber defence

These areas should be treated as part of normal governance and assurance, not as one-off technical tasks. Decision-makers need visibility of which controls are in place, who owns them, what residual risks have been accepted and how control effectiveness will be reviewed over time.

Provider certifications, assurance artefacts and shared responsibility models can support risk assessment, but they do not transfer accountability. Agencies remain responsible for understanding and managing risk.

More cloud policy guidance

Was this information helpful?

Do not include any personal information. We are unable to respond to comments or feedback. If you would like a response, please email, or phone us. Our details are on the AGA contact page www.architecture.digital.gov.au/contact-us.