← Back to glossary

Third-party vendor providing compute/storage/networking services, often acting as a processor.

Definition

A cloud provider supplies infrastructure services (IaaS/PaaS/SaaS components) and may act as a processor or sub-processor. Key considerations include residency, access controls, encryption, logging, and contractual obligations.

In plain English Third-party vendor providing compute/storage/networking services, often acting as a processor.

Why this matters

Why it matters: Cloud architecture choices affect breach impact, lawful access exposure, and compliance.

Example

Example: Encrypt sensitive datasets, restrict admin access, and enforce region pinning for storage and backups.