Using infrastructure you do not own.
WHAT ROLE THE PROVIDER USUALLY HOLDS
Processor.
WHAT YOU REMAIN
The controller, responsible for the data.
WHY THAT MATTERS
Using a provider does not transfer your obligations.
WHAT TO ESTABLISH
Where data is stored and processed Whether it moves between regions Who can access it, including their staff What happens on termination
WHAT TO OBTAIN
A data processing agreement Their security documentation Their sub-processor list
WHAT TO CONFIGURE
Region selection, where offered Encryption Access control Logging
WHY REGION SELECTION MATTERS HERE
It determines whether a transfer occurs, and its latency.
WHAT TO CHECK ABOUT SUPPORT ACCESS
Whether provider staff can view your data, and under what controls.
WHAT TO BE CAREFUL WITH
Default settings, which favour convenience Storage left publicly accessible Snapshots and images containing personal data
WHY PUBLIC STORAGE SPECIFICALLY
It is among the commonest causes of large exposures.
WHAT TO AUDIT
What is publicly reachable.
WHAT TO PLAN
Exit: how you retrieve data and confirm deletion.
WHAT TO DOCUMENT
The assessment of the provider, and the transfer mechanism.