Cloud infrastructure glossary
Plain-language definitions for the terms that come up when you manage infrastructure across more than one cloud - written from the point of view of the team running it, not a single vendor's product page.
BYOC (Bring Your Own Cloud)
BYOC (Bring Your Own Cloud) is a model where a customer connects their existing cloud provider account instead of migrating to a vendor's own infrastructure or a reseller's account. The account, contract, and billing relationship stay with the customer and the provider throughout; the vendor manages resources inside it rather than owning them.
Cloud asset inventory
A cloud asset inventory is a complete, continuously updated record of every resource an organization runs — compute instances, storage volumes, networks, and DNS records — across every connected cloud account and on-premise server, including resources provisioned outside official processes that manual, point-in-time audits routinely miss.
Cloud control plane
A cloud control plane is the layer of interfaces, APIs, and services that let you provision, configure, and manage infrastructure — separate from the data plane, which actually runs your workloads and moves your traffic. Every provider ships its own; the term also covers systems that manage several providers as one plane.
Cloud exit strategy
A cloud exit strategy is a documented plan for moving workloads, data, and configurations off a cloud provider — or between providers — without prolonged downtime, data loss, or loss of negotiating position. It covers data portability, technical dependencies, contractual notice periods, and a tested timeline, and is built before it's needed, not during a crisis.
FinOps
FinOps (financial operations) is the discipline of managing cloud spending as a shared responsibility between engineering, finance, and business teams, using near-real-time cost data to make ongoing trade-offs between speed, cost, and quality — rather than treating cost as a finance-only concern discovered after the invoice arrives.
Fleet management
Fleet management is the practice of inventorying, provisioning, monitoring, patching, and securing a group of servers — cloud instances and on-premise or bare-metal machines alike — as one managed set, using consistent tooling, policy, and an audit trail instead of handling each machine individually by hand.
Hybrid cloud
Hybrid cloud is an IT architecture that combines on-premise or private infrastructure with one or more public cloud providers into a single, coordinated environment rather than isolated silos. Organizations place workloads, data, and management wherever cost, performance, latency, or compliance requirements dictate, typically using shared tooling to provision, secure, and monitor everything consistently.
Immutable audit log
An immutable audit log is an append-only record of system events in which each entry is cryptographically linked to the one before it, so no entry can be edited or deleted without breaking the chain. It provides tamper-evident proof of who did what, and when, across a system's history.
Multi-cloud management
Multi-cloud management is the practice of provisioning, monitoring, securing, and optimizing infrastructure that runs across two or more cloud providers through a single, consistent workflow. It covers inventory, access control, cost tracking, and change auditing for resources that would otherwise require separate consoles, credentials, and processes per provider.
NIS2 evidence
NIS2 evidence is the documented, auditable proof that an organisation's cybersecurity risk-management and incident-response measures required under the EU's NIS2 Directive are actually in place and followed — not the controls themselves, but records (logs, reports, approvals) that let a regulator, auditor, or customer verify they were applied.
Sovereign cloud
Sovereign cloud is infrastructure where data location, the legal jurisdiction governing that data, and the entity operating the systems are all controlled by a single defined authority — typically a country or economic bloc — rather than left to a foreign provider's terms of service. It addresses who can be compelled to hand data over, not just where servers sit.