Cloud services can make email, files and business systems easier to access and manage. They do not remove your legal, contractual or industry responsibilities.
The rules that apply depend on what information your business holds, where it operates and what it has promised customers. Compliance starts with those obligations, not with a list of product settings.
What cloud compliance means
Cloud compliance means using a cloud service in a way that meets the rules and commitments that apply to your business. This may cover privacy, security, record keeping, payment data, health information or a customer contract.
You need to know:
- What data is stored in the service.
- Where the provider stores or processes it.
- Who can access it.
- How access and changes are recorded.
- How the data is backed up, recovered and deleted.
- What happens when the service or contract ends.
Understand shared responsibility
A cloud provider usually protects the buildings, physical equipment and core service. Your business is usually responsible for its users, sign-in settings, access, data and many configuration choices.
The exact split changes between services. A basic hosted server may leave most system management to the customer. A managed software service may handle more of it. Read the provider's responsibility guide and contract for the service you use.
Do not assume that a provider's certification makes your own setup compliant. A secure platform can still be exposed by a weak administrator account, public file link or former employee who retains access.
Work out which rules apply
Australian businesses may need to consider the Privacy Act and Australian Privacy Principles, including the Notifiable Data Breaches scheme. Smaller businesses can still have privacy duties because of their industry, activities or contracts.
Other requirements may apply in specific situations:
- The Payment Card Industry Data Security Standard applies when a business stores, processes or sends payment card data within its scope.
- Health and government work may carry extra rules set by law, funding arrangements or contracts.
- Overseas privacy laws may apply when a business offers services in those markets or handles information about people there.
- Customer contracts may set requirements for storage location, incident reporting, access or deletion.
ISO/IEC 27001 is a standard for managing information security. Certification may provide useful evidence about a provider or business, but it is not a substitute for checking the laws and contracts that apply to you.
Use legal or compliance advice when the scope is unclear.
Check where data is handled
A provider's Australian office does not prove that all data stays in Australia. Backups, support access and connected services may involve other countries.
Ask the provider where customer data and backups are stored, whether support staff in other locations can access them and how it handles government or legal requests. Compare the answers with your privacy notice, customer commitments and industry rules.
Control access
Give people only the access they need for their work. Use separate administrator accounts, protect them with strong multi-factor authentication and review access regularly.
Remove access promptly when a staff member or contractor leaves. Review service accounts and connected apps as well as normal user accounts. These are easy to forget and may retain broad access.
Protect and recover data
Use the security options supported by the service and suitable for the data. This may include encryption, restrictions on sharing, protected backups and controls for downloading information to personal devices.
Do not assume the provider's backup meets your recovery needs. Ask what it covers, how long information is retained and how quickly it can be restored. Test the recovery process for important systems.
Keep useful records
Turn on logging that records important sign-ins, access changes and administrator actions. Decide who reviews alerts and how long the records are kept.
Collecting logs without anyone looking at them does not help. Focus on events your team or IT provider can investigate and act on.
Review suppliers and changes
Before adopting a cloud service, review its security information, contract, support arrangements and exit process. Record who approved it and what business data it may hold.
Repeat the review when the provider changes important terms, the business adds sensitive data or staff start using the service in a new way.
Train staff on the actual system
Show staff how to share files safely, report an unexpected sign-in and check who can see a document. Training should reflect the cloud services they use every day.
Cloud compliance is ongoing work, but it does not need to become a wall of technical language.
When you cannot map which cloud services hold business data, book a cloud systems consultation with JCPIT Support. We will document the technology side, including access, Microsoft 365 settings, backups and security controls. Use a qualified adviser to confirm the legal or contractual requirements.