Introduction
Cloud computing allows people and organizations to use computing resources—such as servers, storage, databases, networks, and software—over a network when they need them. Instead of purchasing and operating every piece of computing equipment themselves, users can obtain resources from a cloud provider and scale them according to demand.
The U.S. National Institute of Standards and Technology (NIST) defines cloud computing as a model that provides convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provided and released with minimal management effort. NIST identifies five essential characteristics, three service models, and four deployment models.
Behind many cloud services are data centers: physical facilities containing computing, storage, and networking equipment. Data centers also need electrical power systems, backup power, cooling, environmental controls, physical security, and high-speed network connections.
Understanding both concepts is important because cloud computing describes how computing resources are delivered, while data centers provide much of the physical infrastructure that makes those services possible.
Learning Objectives
After studying this guide, you should be able to:
Explain cloud computing and its five main characteristics.
Distinguish between IaaS, PaaS, and SaaS.
Compare public, private, community, and hybrid clouds.
Identify the main components of a data center.
Explain virtualization, virtual machines, containers, scalability, and redundancy.
Describe major cloud and data-center security, reliability, and energy considerations.
What is Cloud Computing?
Cloud computing is a method of delivering computing capabilities as services.
Instead of running every application on a computer located in the same building as the user, organizations can access remote computing systems through networks such as the Internet.
Examples of resources that can be delivered through cloud systems include:
Processing power
Virtual servers
Data storage
Databases
Networking
Development platforms
Business applications
Backup systems
Cloud computing does not simply mean "using another computer over the Internet." A true cloud service normally includes characteristics such as automated provisioning, shared resources, rapid scaling, network access, and measurable resource use.
Five Essential Characteristics of Cloud Computing
NIST identifies five characteristics that define its cloud computing model.
Characteristic | Meaning |
On-demand self-service | Users can obtain computing resources automatically when needed. |
Broad network access | Services are available through networks and standard access mechanisms. |
Resource pooling | Computing resources are shared among multiple users or customers. |
Rapid elasticity | Resources can expand or shrink quickly according to demand. |
Measured service | Resource use can be monitored, measured, and often billed accordingly. |
On-Demand Self-Service
A cloud customer can provision resources without requiring a provider employee to manually install every server.
For example, a developer might create a new virtual server through a management console or application programming interface.
Broad Network Access
Cloud services are accessible through networks using devices such as:
Desktop computers
Laptops
Smartphones
Tablets
Servers
This makes cloud applications available from many different locations.
Resource Pooling
Cloud providers combine computing resources into large shared pools.
Different customers can use parts of this infrastructure while their workloads and data remain logically separated. This arrangement is often called multi-tenancy.
Rapid Elasticity
Cloud resources can respond to changing demand.
For example, an online store may require many more servers during a major sales event. Cloud infrastructure can increase available capacity and later reduce it when demand falls.
Measured Service
Cloud systems measure resource consumption.
Providers may measure:
Processing time
Storage capacity
Network traffic
Number of requests
Active users
This supports monitoring and usage-based charging.
Cloud Service Models
NIST defines three major service models:
Infrastructure as a Service
Platform as a Service
Software as a Service
Infrastructure as a Service — IaaS
Infrastructure as a Service (IaaS) provides basic computing infrastructure such as virtual machines, networking, and storage.
The provider manages the physical infrastructure, while customers typically manage their operating systems, applications, and much of their software configuration.
Typical IaaS resources include:
Virtual servers
Virtual networks
Storage volumes
Firewalls
Load balancers
IaaS offers considerable control but also gives the customer more management responsibility.
Platform as a Service — PaaS
Platform as a Service (PaaS) provides an environment in which developers can build and deploy applications without managing much of the underlying server infrastructure.
The provider typically manages infrastructure and platform components such as operating systems or runtime environments.
Developers can concentrate more heavily on:
Application code
Business logic
Data
Application configuration
Software as a Service — SaaS
Software as a Service (SaaS) provides complete applications to users.
The cloud provider manages the infrastructure and application platform, while the user accesses the software through an interface such as a browser or application.
Web-based email and online productivity applications are common examples of the SaaS approach.
IaaS vs PaaS vs SaaS
Model | What the Customer Mainly Uses | Customer Control | Provider Responsibility |
IaaS | Infrastructure | High | Physical hardware and virtualization infrastructure |
PaaS | Development platform | Medium | Infrastructure plus much of the software platform |
SaaS | Finished application | Lower | Application, platform, and infrastructure |
A useful memory rule is:
IaaS = rent infrastructure
PaaS = rent a development environment
SaaS = use finished software
Cloud Deployment Models
NIST identifies four deployment models.
Public Cloud
A public cloud provides cloud infrastructure for use by customers of a cloud provider.
Organizations generally share the provider's large infrastructure while maintaining logical separation between customers.
Private Cloud
A private cloud is operated for the exclusive use of one organization.
It may exist:
Inside the organization's own data center
At another facility
Under the management of the organization or another provider
Private cloud is not simply another name for a traditional private data center. To fit the cloud model, the environment should provide cloud characteristics such as self-service, resource pooling, and elasticity.
Community Cloud
A community cloud serves organizations that share particular requirements or concerns.
For example, several organizations within the same sector could share infrastructure designed around common security or compliance needs.
Hybrid Cloud
A hybrid cloud combines two or more distinct cloud environments that remain separate but are connected in ways that allow data or applications to move between them.
One common arrangement combines private infrastructure with public cloud resources.
Deployment Model | Primary Users | Main Idea |
Public | Multiple customers | Provider-operated shared cloud |
Private | One organization | Dedicated organizational cloud |
Community | Related organizations | Shared requirements |
Hybrid | Combination | Connected cloud environments |
What is a Data Center?
A data center is a facility designed to house and operate information technology equipment.
Data centers primarily contain equipment for:
Processing data
Storing data
Transmitting data
They also require supporting systems that provide reliable electricity and suitable environmental conditions.
A data center can range from a small server room to an enormous facility containing thousands of servers.
Main Components of a Data Center
1. Servers
Servers perform computing tasks.
They may:
Run websites
Process transactions
Execute applications
Host virtual machines
Perform scientific calculations
Run artificial intelligence workloads
Many servers are mounted inside standardized equipment racks.
2. Storage Systems
Storage systems hold digital information.
Common storage technologies include:
Hard disk drives
Solid-state drives
Storage arrays
Network-attached storage
Distributed storage systems
Cloud storage often spreads data across multiple physical devices or locations for capacity and resilience.
3. Networking Equipment
Networking connects servers, storage devices, users, and other data centers.
Important devices include:
Switches
Routers
Firewalls
Network interfaces
Load balancers
High-speed networks allow large quantities of information to move between systems.
4. Power Infrastructure
Servers cannot operate without reliable electricity.
Data centers therefore may include:
Power distribution systems
Uninterruptible power supplies (UPS)
Batteries
Backup generators
Electrical monitoring equipment
Redundant power systems help services continue operating when individual components fail.
5. Cooling Systems
Computer hardware produces heat.
If equipment becomes too hot, its performance and reliability can suffer. Data centers therefore use cooling and airflow-management systems to keep equipment within acceptable environmental conditions.
DOE identifies IT systems, airflow management, cooling, electrical systems, environmental conditions, and heat recovery as major areas of energy-efficient data-center design.
6. Physical Security
Because data centers contain valuable equipment and information, physical protection may include:
Controlled entrances
Security personnel
Surveillance systems
Access cards
Biometric systems
Locked equipment areas
Cybersecurity protects digital systems, while physical security protects the facility and hardware.
Types of Data Centers
Data centers can be classified according to their purpose and operating model.
The U.S. Department of Energy discusses categories including small data centers, colocation facilities, enterprise facilities, high-performance computing facilities, and hyperscale centers.
Type | Description |
Enterprise | Operated primarily for one organization's IT requirements |
Colocation | Space, power, and cooling are rented to multiple customers |
Hyperscale | Very large facilities commonly associated with major cloud and technology providers |
HPC | Designed for high-performance computing and intensive calculations |
Small data center | Smaller facility or computer room supporting limited infrastructure |
How Cloud Computing and Data Centers Work Together
Cloud computing and data centers are closely related but are not the same thing.
A useful distinction is:
Data center = physical infrastructure
Cloud computing = service-delivery model
A cloud provider may operate multiple data centers containing servers, networking systems, storage devices, and supporting infrastructure. Software then pools and abstracts those physical resources so customers can request computing capabilities on demand.
Therefore:
Physical Data Center
↓
Servers + Storage + Networking
↓
Virtualization / Resource Abstraction
↓
Cloud Platform
↓
IaaS / PaaS / SaaS
↓
Users and Applications
Not every data center is a cloud, but cloud computing ultimately depends on physical computing infrastructure somewhere.
Virtualization
Virtualization allows software to create virtual versions of computing resources.
A powerful physical server can, for example, host several virtual machines (VMs). Each virtual machine can behave much like an independent computer.
A software layer known as a hypervisor helps create and manage virtual machines.
NIST notes that full virtualization allows one or more operating systems and their applications to operate using virtual hardware, and that virtualization is widely used to improve operational efficiency, including in cloud computing.
Why Virtualization Matters
Without virtualization:
One physical server → One main operating environment
With virtualization:
One physical server
├── Virtual Machine 1
├── Virtual Machine 2
├── Virtual Machine 3
└── Virtual Machine 4
This can improve hardware utilization and allow workloads to be created, moved, or removed more flexibly.
Containers
A container packages an application with the components needed to run it while using operating-system-level virtualization.
Containers are generally more lightweight than complete virtual machines because they do not normally require a separate full guest operating system for every application.
NIST describes containers as a combination of operating-system virtualization and application packaging that provides a portable, reusable, and automatable method for running applications.
Virtual Machine vs Container
Feature | Virtual Machine | Container |
Virtualizes | Hardware environment | Operating-system environment |
Guest OS | Usually included | Usually shares host OS kernel |
Typical size | Larger | Smaller |
Startup | Usually slower | Usually faster |
Isolation | Strong VM boundary | Container isolation |
Common use | Full systems and isolated workloads | Cloud-native applications and services |
Scalability and Elasticity
These terms are related but not identical.
Scalability is the ability of a system to handle increasing workloads by adding resources.
Elasticity is the ability to increase or decrease resources dynamically as demand changes.
Two common scaling approaches are:
Vertical Scaling
Increase the resources of one machine.
Example:
4 GB RAM → 16 GB RAM
Horizontal Scaling
Add more machines or instances.
Example:
2 servers → 10 servers
Cloud systems frequently use horizontal scaling because workloads can be distributed across multiple computing instances.
Load Balancing
A load balancer distributes requests or workloads among several computing resources.
For example:
Users
↓
Load Balancer
↙ ↓ ↘
S1 S2 S3
Instead of every request going to one server, traffic is distributed among multiple servers.
Load balancing can:
Improve performance
Reduce overload
Support scaling
Improve service availability
Redundancy and High Availability
Important digital services must continue operating even when individual components fail.
Redundancy means providing additional components or systems that can take over after a failure.
Examples include:
Multiple servers
Backup network links
Duplicate power supplies
Multiple storage copies
Backup generators
High availability refers to designing systems so that services remain accessible for a very high proportion of time.
Redundancy is one technique used to achieve high availability.
Cloud Security
Moving applications and data to cloud systems does not eliminate security responsibilities.
NIST identifies security and privacy as major considerations when organizations use public cloud environments.
Important controls include:
Identity and Access Management
Systems should determine:
Who the user is
What the user is allowed to access
Which actions the user may perform
Encryption
Encryption converts readable data into protected form using cryptographic techniques.
Encryption may protect:
Data stored on disks
Data transmitted across networks
Authentication
Authentication verifies an identity.
Examples include:
Passwords
Security keys
One-time codes
Multi-factor authentication
Network Security
Firewalls, segmentation, monitoring systems, and access policies help control network communication.
Updates and Vulnerability Management
Cloud applications, operating systems, containers, and other software need security updates to address known weaknesses.
Zero Trust
A zero-trust security model does not automatically trust a user or device simply because it is inside a particular network.
NIST explains that zero trust focuses on protecting resources and does not grant implicit trust based solely on physical or network location.
Advantages of Cloud Computing
Cloud computing can provide several operational advantages:
Resources can be obtained rapidly.
Capacity can scale with demand.
Users can access services through networks.
Organizations may avoid purchasing some infrastructure in advance.
Usage can be measured.
Services can be automated through software interfaces.
Infrastructure can be distributed across multiple facilities.
However, NIST advises organizations to evaluate both opportunities and risks when deciding how cloud computing should be used.
Challenges and Limitations
Cloud computing also creates challenges.
Security and Privacy
Organizations must protect data and control access even when infrastructure is operated by another organization.
Internet and Network Dependence
Many cloud applications depend on reliable network connectivity.
Provider Dependence
Applications that rely heavily on provider-specific technology can become difficult or expensive to move elsewhere. This issue is often called vendor lock-in.
Cost Management
Cloud resources can be provisioned easily, but unused or poorly managed resources may create unnecessary expenses.
Compliance
Organizations may have legal or regulatory requirements governing where data is stored and how it is protected.
Outages
Cloud platforms can experience hardware, software, network, power, or configuration failures. Reliable applications therefore require good architectural planning rather than assuming that individual components can never fail.
Data Centers and Energy Use
Data centers require electricity for computing equipment and supporting infrastructure such as cooling and power conversion.
The U.S. Department of Energy describes data centers as highly energy-intensive facilities and emphasizes opportunities to improve efficiency through better IT systems, power systems, cooling, airflow management, monitoring, and facility design.
Important efficiency techniques include:
Server consolidation
Virtualization
Efficient processors and servers
Improved airflow management
Efficient cooling
Monitoring energy use
Matching infrastructure capacity to actual demand
Energy efficiency matters because reducing unnecessary IT power consumption can also reduce the amount of cooling and electrical infrastructure required.
Cloud Computing vs Traditional On-Premises Computing
Feature | Cloud Computing | Traditional On-Premises |
Infrastructure ownership | Often provider-operated | Usually organization-operated |
Provisioning | Often automated | May require hardware installation |
Scaling | Usually rapid | Often slower |
Initial hardware purchase | Often reduced | Usually required |
Physical maintenance | Often provider responsibility | Organization responsibility |
Control | Depends on service model | Usually high |
Resource measurement | Core cloud characteristic | Varies |
Access | Network-oriented | Usually organizational infrastructure |
Neither approach is automatically correct for every workload. Organizations may use both, leading to hybrid environments.
Common Mistakes
Mistake 1: Cloud Means the Internet
The Internet is often used to access cloud services, but cloud computing is a computing model with specific characteristics. Internet access alone does not make a service a cloud.
Mistake 2: Cloud and Data Center Mean the Same Thing
A data center is a physical facility. Cloud computing is a method of delivering computing resources.
Mistake 3: Every Remote Server Is a Cloud Server
Simply accessing a remote computer does not necessarily meet the NIST cloud characteristics.
Mistake 4: Virtualization and Cloud Computing Are Identical
Virtualization is an enabling technology. Cloud computing adds capabilities such as self-service, pooling, elasticity, network access, and measured service.
Mistake 5: SaaS Gives the Customer the Most Infrastructure Control
The opposite is generally true. IaaS normally provides customers with more control over operating environments than SaaS.
Memory Tips
Remember the three service models as:
I-P-S
IaaS — Infrastructure
PaaS — Platform
SaaS — Software
Remember the four traditional NIST deployment models as:
P-P-C-H
Public
Private
Community
Hybrid
For cloud versus data center, remember:
Cloud = service
Data center = facility
Summary
Cloud computing provides on-demand access to shared computing resources such as processing, storage, networks, and applications. According to NIST, the cloud model has five essential characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. The three major service models are IaaS, PaaS, and SaaS, while the four NIST deployment models are public, private, community, and hybrid cloud.
Data centers provide the physical foundation for much of modern computing. They contain servers, storage equipment, networking systems, power infrastructure, cooling systems, and physical security controls. Virtualization allows multiple virtual machines to share physical infrastructure, while containers provide a lightweight method of packaging and operating applications. Techniques such as load balancing, redundancy, scaling, encryption, and identity management help cloud systems deliver reliable and secure services.
FAQ
1. What is cloud computing?
Cloud computing is a model for providing configurable computing resources through networks on demand, with characteristics such as resource pooling, rapid elasticity, and measured service.
2. What are the five characteristics of cloud computing?
They are on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.
3. What are the three cloud service models?
The three NIST service models are Infrastructure as a Service, Platform as a Service, and Software as a Service.
4. What is the difference between cloud computing and a data center?
A data center is a physical facility containing IT equipment and supporting infrastructure. Cloud computing is a model for delivering computing capabilities from pooled resources.
5. What is virtualization?
Virtualization uses software to create virtual computing environments. Multiple virtual machines can operate on physical hardware while functioning as separate systems.
6. What is a container?
A container packages applications using operating-system virtualization. Containers are designed to make applications portable and easier to automate and deploy.
7. What is a hybrid cloud?
A hybrid cloud combines distinct cloud environments, such as private and public clouds, while allowing appropriate data or application portability between them.
8. Why do data centers need cooling?
Servers and other electronic equipment produce heat. Cooling and airflow systems remove that heat and maintain suitable operating conditions.
9. Why is redundancy used in data centers?
Redundancy provides backup components so that a single failure does not necessarily interrupt an entire service.
10. Is every data center a cloud?
No. A traditional data center may host servers without providing all the characteristics required for cloud computing, such as on-demand self-service and rapid elasticity.
Key Takeaways
Cloud computing delivers shared computing resources as scalable, on-demand services.
The three principal NIST service models are IaaS, PaaS, and SaaS.
Data centers contain the physical servers, storage, networks, electrical systems, and cooling infrastructure used to operate digital services.
Virtualization, containers, load balancing, redundancy, and automation are important technologies in modern cloud and data-center environments.
Security, reliability, energy efficiency, performance, compliance, and cost must all be considered when designing cloud systems.
References
National Institute of Standards and Technology (NIST) — The NIST Definition of Cloud Computing, SP 800-145. Defines cloud computing, its five essential characteristics, three service models, and four deployment models. NIST SP 800-145
National Institute of Standards and Technology (NIST) — Cloud Computing Synopsis and Recommendations, SP 800-146. Covers cloud technologies, benefits, risks, configurations, performance, reliability, and deployment considerations. NIST SP 800-146
National Institute of Standards and Technology (NIST) — Guidelines on Security and Privacy in Public Cloud Computing, SP 800-144. Discusses security and privacy considerations associated with public cloud environments. NIST SP 800-144
National Institute of Standards and Technology (NIST) — Guide to Security for Full Virtualization Technologies, SP 800-125. Explains full virtualization, virtual machines, hypervisors, and related security considerations. NIST SP 800-125
National Institute of Standards and Technology (NIST) — Application Container Security Guide, SP 800-190. Explains application containers, operating-system virtualization, container packaging, and security. NIST SP 800-190
National Institute of Standards and Technology (NIST) — Zero Trust Architecture, SP 800-207. Provides principles and architectural guidance for zero-trust security. NIST SP 800-207
U.S. Department of Energy — Data Centers and Servers. Provides information about data-center energy use and opportunities for improved efficiency. DOE Data Centers and Servers
U.S. Department of Energy, Federal Energy Management Program — Best Practices Guide for Energy-Efficient Data Center Design. Covers IT systems, environmental conditions, airflow management, cooling, electrical infrastructure, heat recovery, and efficiency metrics. DOE Energy-Efficient Data Center Design