What is cloud storage?
Cloud storage keeps your files on a provider’s equipment and delivers them over the internet. Where the data lives, how safe it is and who can read it.
Cloud storage means keeping your data on equipment that a provider owns and runs, and reaching it over the internet. The provider looks after the drives, the buildings and the power. You pay for the space you use and can have more whenever you need it.
The US standards body NIST names storage as one of the resources a cloud provider pools and shares among its customers. The shared drive inside Microsoft 365 or Google Workspace is cloud storage. So is the place an online backup service sends its copies.
Where the data lives
The data sits on drives in the provider’s data centres. NIST notes that a cloud customer generally does not know the exact location, but can often choose it at a broader level, such as the country or the state. With the large providers that choice is called a region, and you make it when the storage is created.
Inside the region, the provider keeps more than one copy. Standard Amazon S3 storage spreads data across at least three separate sites in one region. Google Cloud Storage uses at least two zones for a regional store. Azure Storage has several options, from copies inside one data centre up to a second set in another region hundreds of miles away.
The Australian Signals Directorate advises using cloud services located in countries that suit the sensitivity of your data. Ask your provider which region holds yours, and whether any copy leaves Australia.
Durability and availability
Providers describe storage with two words that are easy to confuse. Google defines them plainly: durability is long-term protection that keeps data intact and uncorrupted, and availability is the ability to reach the data immediately when you ask for it.
The figures are written as percentages. Amazon says standard S3 storage is designed for 99.999999999% durability and 99.99% availability over a year. Google and Microsoft quote durability of at least eleven nines for their standard options. These are design targets. Durability is the higher of the two numbers: a service can be out of reach for an hour without anything being lost.
Who can read it
The provider supplies the locks. Azure Storage encrypts all data written to it and requires every request to be authorised. New Amazon S3 stores do not allow public access by default. Those defaults can be changed by anyone with permission to do so, and one changed setting can open a private store to the internet.
Deciding who holds the keys is the customer’s job. The Australian Signals Directorate lists it among the responsibilities that always stay with you: control who can access your data, and give people only the access they need. In practice:
- Turn on multi-factor authentication for every account that can reach the storage.
- Review who has access when someone changes role or leaves.
- Check for folders or links shared with “anyone”, and close the ones nobody needs.
Cloud storage is one copy, however many times the provider duplicates it. The 3-2-1 backup rule explains how many copies to keep and where, and our storage page covers setting it up.
Sources
- SP 800-145: The NIST definition of cloud computing (NIST) csrc.nist.gov
- What is cloud storage? (Amazon Web Services) aws.amazon.com
- Data protection in Amazon S3 (AWS Documentation) docs.aws.amazon.com
- Blocking public access to your Amazon S3 storage (AWS Documentation) docs.aws.amazon.com
- Azure Storage redundancy (Microsoft Learn) learn.microsoft.com
- Introduction to Azure Storage (Microsoft Learn) learn.microsoft.com
- Data availability and durability in Cloud Storage (Google Cloud Documentation) docs.cloud.google.com
- Cloud shared responsibility model: guidance for individuals and small and medium businesses (Australian Signals Directorate) cyber.gov.au