Managing the risk of cloud-enabled products

Document preview6 pages
Cover of Managing the risk of cloud-enabled products
Page 1 of 6

Download this document free

Get this document with your free trial. Choose from the full Complyzard library.

Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.
Document information

Guidance outlining the risks of locally installed products interacting with cloud services, and suggestions to help organisations manage this risk.

Adapted edition

Document type
Reference Guide
Format
DOCX
Pages
6
Language
English
Version
1.0
Updated
2026-09-16
Description

Guidance outlining the risks of locally installed products interacting with cloud services, and suggestions to help organisations manage this risk for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.

Contents
  • Understanding how products interact with cloud services
  • 1. Vendor statements (including terms and conditions or privacy policies)
  • 2. Independent research
  • 3. Your own investigations
  • Understanding the security implications for your systems
  • What information can the product access?
  • What do you know about the cloud service(s) involved?
  • Managing the risks of cloud interactions
  • 1. Use in-built controls to control data flow and remote access
  • Warning
  • 2. Use network-level controls to manage data flows with services
  • 3. Use network monitoring to maintain awareness
  • 4. Consider contractual controls
  • 5. Enable automatic updates
  • 6. Consider data sharing mechanisms
  • 7. Review service periodically
  • Source links
Source and licence
Managing the risk of cloud-enabled products

National Cyber Security Centre

AttributionNational Cyber Security Centre, “Managing the risk of cloud-enabled products” (30 November 2017), reused under the Open Government Licence v3.0.

ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.

Version history
  • v1.016/09/2026
Report this document