Agree responsibility before configuration begins
Architecture should define who owns the cloud account, networking, backups, monitoring, encryption, operating-system maintenance, database administration, support access and disaster recovery.
Write down what each side owns
A private cloud is not automatically more secure; security depends on how the environment is designed and operated.
Before commitment: This website explains the approach. The accepted project documents define infrastructure ownership, service levels, security requirements, migration depth, integrations, support and acceptance criteria.
