Skip to content
IT Atlas

Cloud · Cloud Governance

Cloud Governance

Guardrails that keep cloud usage consistent, compliant and affordable: policy as code, landing zones, tagging and permission boundaries.

IntermediateUpdated 2026-09-01

Overview

Governance in cloud is preventive where possible and detective where not. Policy engines, Azure Policy, AWS SCPs and Config, GCP organisation policies, deny non compliant resource creation, while posture tools flag drift that slipped through.

Landing zones encode the decisions once: naming, tagging, region restrictions, network topology, identity model, logging destinations and baseline security controls.

Security considerations

  • Deny creation of resources in unapproved regions and prevent disabling of audit logging.
  • Require encryption and private networking by policy rather than by review.