How unit 1 is examined
This unit covers the NIST definition and reference architecture, the five characteristics, the three service models, the four deployment models and the benefits; marks sit on characteristics, the NIST architecture, deployment models and service models.
Definition
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (networks, servers, storage, applications, services) that can be rapidly provisioned and released with minimal management effort (NIST).</mark>
Key points.
- The NIST reference architecture is a vendor-neutral model that shows the actors, activities and functions of cloud computing.
- It has five actors: Consumer (uses the service), Provider (delivers it), Broker (intermediates and combines services), Auditor (independently checks security, privacy and performance) and Carrier (network and telecom link that transports the service).
- The provider handles service orchestration, cloud management and security across the SaaS, PaaS and IaaS layers.
Diagram. <figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u1-01" viewBox="0 0 424 424" width="424" height="424" role="img" aria-label="NIST architecture. Con = Consumer, Bro = Broker, Pro = Provider, Aud = Auditor, Car = Carrier"><style>#dsfig-u1-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u1-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u1-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u1-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u1-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u1-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u1-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u1-01 .t{fill:#16181D;font-weight:500}#dsfig-u1-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u1-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u1-01 .dot{fill:#16181D}#dsfig-u1-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u1-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u1-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u1-01 .ah{fill:#454C5A}#dsfig-u1-01 .ah.hi{fill:#2340B8}#dsfig-u1-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u1-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u1-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u1-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u1-01 .e{stroke:#B1B7C3}html.dark #dsfig-u1-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u1-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u1-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u1-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u1-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u1-01 .t{fill:#E6E8ED}html.dark #dsfig-u1-01 .t.inv{fill:#0F1115}html.dark #dsfig-u1-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u1-01 .dot{fill:#E6E8ED}html.dark #dsfig-u1-01 .ann{fill:#8FA3FF}html.dark #dsfig-u1-01 .lbl{fill:#858D9C}html.dark #dsfig-u1-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u1-01 .ah{fill:#B1B7C3}html.dark #dsfig-u1-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u1-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u1-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u1-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah1" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh1" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M54.8,197.2 L197.2,54.8" marker-end="url(#ah1)" marker-start="url(#ah1)"/><path class="e" d="M212,61 L212,191" marker-end="url(#ah1)" marker-start="url(#ah1)"/><path class="e" d="M61,212 L191,212" marker-end="url(#ah1)" marker-start="url(#ah1)"/><path class="e" d="M212,233 L212,363" marker-end="url(#ah1)" marker-start="url(#ah1)"/><path class="e" d="M53.4,225.4 L197.2,369.2" marker-end="url(#ah1)"/><path class="e" d="M233,212 L363,212" marker-end="url(#ah1)" marker-start="url(#ah1)"/><path class="e" d="M61,212 L363,212" marker-end="url(#ah1)" marker-start="url(#ah1)"/><circle class="n" cx="40" cy="212" r="18"/><text class="t" x="40" y="212" dy=".35em" text-anchor="middle">Con</text><circle class="n" cx="212" cy="40" r="18"/><text class="t" x="212" y="40" dy=".35em" text-anchor="middle">Bro</text><circle class="n" cx="212" cy="212" r="18"/><text class="t" x="212" y="212" dy=".35em" text-anchor="middle">Pro</text><circle class="n" cx="212" cy="384" r="18"/><text class="t" x="212" y="384" dy=".35em" text-anchor="middle">Aud</text><circle class="n" cx="384" cy="212" r="18"/><text class="t" x="384" y="212" dy=".35em" text-anchor="middle">Car</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">NIST architecture. Con = Consumer, Bro = Broker, Pro = Provider, Aud = Auditor, Car = Carrier</figcaption></figure>
Asked: [7 marks] (Dec 2024) Define NIST cloud computing reference architecture.
Characteristics
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. <mark>NIST lists five essential characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.</mark>
Key points.
- On-demand self-service means a consumer provisions computing capacity such as server time or storage automatically, without human interaction with the provider.
- Broad network access means capabilities are available over the network and used through standard mechanisms from phones, tablets and laptops.
- Resource pooling means the provider serves many consumers from one pool using a multi-tenant model, and resources are dynamically assigned and reassigned by demand.
- Rapid elasticity means capabilities scale out and in quickly, often automatically, and appear unlimited to the consumer.
- Measured service means usage is metered and monitored, so it is controlled, reported and billed on a pay-per-use basis.
- On-demand functionality is provided by automated provisioning through a web portal or API, backed by virtualised pools and metering; example: launching an AWS EC2 instance in minutes and paying per hour.
Answer frame. Open with the NIST definition of cloud computing; list the five characteristics and develop points 1-5 in order with one example each; for the on-demand question define self-service, then develop point 6 (portal or API, automation, pay-per-use, broad access); close with one line that these five make cloud different from traditional hosting.
Pitfall: Do not confuse elasticity (scaling with demand) with resource pooling (sharing among tenants).
Asked: [7 marks] (Dec 2024) What are the characteristics of cloud computing? Asked: [7 marks] (Dec 2024) What is on-demand functionality? How is it provided in cloud computing?
Components
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A cloud has three main components: clients, the datacenter and distributed servers.</mark>
Key points.
- Clients are the devices, such as laptops, mobiles and thin clients, that users employ to reach cloud services through a browser or app.
- The datacenter is the collection of servers, storage and networking where applications and data are hosted, often as virtual machines.
- Distributed servers are placed at different locations, giving fault tolerance, speed and redundancy if one site fails.
Software as a Service
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>SaaS delivers a complete application over the internet, which the consumer uses through a browser without managing any underlying infrastructure.</mark>
Key points.
- The provider manages application, data, servers and storage; the user only configures and uses the software.
- It is billed as a subscription and is accessible from any device.
- Examples are Salesforce, Gmail and Google Docs.
- The limit is that the user has almost no control over features or the underlying system.
Platform as a Service
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>PaaS gives developers a ready platform (runtime, middleware, database and tools) to build, test and deploy applications without managing servers.</mark>
Key points.
- The provider manages OS, servers and runtime; the developer controls only the application and its data.
- It speeds development and scales automatically with load.
- Examples are Google App Engine, Microsoft Azure App Service and Heroku.
- The limit is vendor lock-in to the provider's languages and tools.
Infrastructure as Service
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>IaaS provides virtualised computing resources (virtual machines, storage and networks) on demand, over the internet, on a pay-as-you-go basis.</mark>
Key points.
- The provider manages hardware and virtualisation; the consumer installs and controls the OS, middleware and applications.
- It gives the highest control and flexibility of the three models.
- Examples are AWS EC2, Google Compute Engine and Azure Virtual Machines.
- It suits variable workloads, testing and disaster recovery without buying hardware.
Service models and scalability.
| Model | Consumer controls | Abstraction | Example |
|---|---|---|---|
| IaaS | OS, middleware, apps | Lowest | AWS EC2 |
| PaaS | Apps and data | Medium | Google App Engine |
| SaaS | Only settings | Highest | Salesforce |
Flexibility: IaaS gives a free choice of stack, PaaS speeds development and SaaS removes all setup, so each user picks the level of control needed. Scalability: all three give on-demand resources, elastic auto-scaling and pay-as-you-go billing, so capacity follows load.
Asked: [7 marks] (Jun 2025) How do cloud service models (IaaS, PaaS and SaaS) contribute to the flexibility and scalability of cloud computing?
Public clouds
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A public cloud is owned and operated by a third-party provider and offered to the general public over the internet.</mark>
Key points.
- Resources are shared among many tenants, with no upfront capital cost and pay-per-use billing.
- It scales almost without limit and needs no maintenance by the user.
- Examples are AWS, Microsoft Azure and Google Cloud.
- Security and control are weaker than in a private cloud.
Private clouds
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A private cloud is operated for a single organisation, hosted on-premise or by a third party.</mark>
Key points.
- It gives the highest security, control and compliance.
- Cost is high because the organisation buys and maintains the infrastructure.
- Scalability is limited to the capacity owned.
- Examples are a bank or a government's internal cloud, or OpenStack-based enterprise clouds.
Community clouds
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A community cloud is shared by several organisations with common concerns (mission, security or compliance) and managed by them or a third party.</mark>
Key points.
- Cost is split among members, so it is cheaper than private and more secure than public.
- Examples are a cloud shared by government departments, hospitals or universities for research.
- Limits are less capacity than public and shared governance.
Hybrid clouds
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>A hybrid cloud combines two or more distinct clouds (private, community or public) that stay separate but are bound by technology allowing data and application portability.</mark>
Key points.
- Sensitive data and core systems stay in the private cloud, while the public cloud handles peaks ("cloud bursting").
- Example: an online retailer keeps customer records privately and rents public capacity in a festive sale.
- It balances cost, security and scalability but is complex to manage.
Comparison of deployment models.
| Basis | Public | Private | Community | Hybrid |
|---|---|---|---|---|
| Ownership | Provider | Single organisation | Group of organisations | Mixed |
| Access | Anyone | Organisation only | Community members | Both |
| Cost | Lowest, pay-per-use | Highest | Shared, medium | Medium |
| Security | Lowest | Highest | High | High for sensitive data |
| Scalability | Very high | Limited | Limited | High via bursting |
| Example | AWS | Bank cloud | Government cloud | Retailer bursting |
Asked: [7 marks] (Dec 2024) Explain hybrid and community cloud with examples. Asked: [7 marks] (Jun 2025) Compare and contrast different cloud deployment models: Public, Private, Hybrid and Community clouds.
Advantages of Cloud computing
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Cloud computing lets users rent resources on demand instead of owning them, giving lower cost, scalability and access from anywhere.</mark>
Key points.
- There is no upfront hardware cost, and pay-per-use turns capital expense into operating expense.
- Resources scale up and down quickly with demand.
- Data and services are accessible from anywhere on any device, with high availability and backup.
- Social networking: Facebook, Twitter and LinkedIn use cloud storage and scaling to hold billions of photos and posts, serve peak traffic, run analytics and stay available worldwide.
Asked: [7 marks] (Dec 2024) Briefly explain the applications of cloud computing in the field of social networking.
Comparing cloud providers with traditional IT service providers
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Cloud providers rent shared, elastic resources on pay-per-use terms, whereas traditional IT providers supply fixed, dedicated hardware and software under long contracts.</mark>
Key points.
- Cloud has no upfront cost; traditional IT needs heavy capital investment.
- Cloud provisions in minutes; traditional IT takes weeks.
- Cloud scales elastically; traditional capacity is fixed.
- Traditional IT gives more physical control, while cloud shifts maintenance to the provider.
Last-minute revision
- Cloud computing (NIST): on-demand network access to a shared pool of configurable resources, minimal management effort.
- Five characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service.
- NIST actors: Consumer, Provider, Broker, Auditor, Carrier.
- Service models: IaaS (EC2), PaaS (App Engine), SaaS (Salesforce).
- Control falls and abstraction rises from IaaS to PaaS to SaaS.
- Deployment models: public, private, community, hybrid.
- Public is cheapest and most scalable; private is the most secure.
- Community is shared by organisations with common concerns.
- Hybrid uses cloud bursting to public cloud.
- Cloud converts capital expense into operating expense.
Memory hooks
- On-demand, Broad, Pool, Elastic, Measured: "OBPEM".
- NIST actors: "CPB-AC", Consumer, Provider, Broker, Auditor, Carrier.
- Service stack: I-P-S means Infrastructure, Platform, Software, with control falling.
- Deployment: "Pu-Pr-Co-Hy", from widest to narrowest access.
Coverage checklist
- Definition: NIST definition and reference architecture (Dec 2024).
- Characteristics: characteristics; on-demand functionality (Dec 2024).
- Components: clients, datacenter, distributed servers.
- Software as a Service: SaaS (Jun 2025 model question).
- Platform as a Service: PaaS (Jun 2025 model question).
- Infrastructure as Service: IaaS and service-model table (Jun 2025).
- Public clouds: public cloud (Jun 2025 comparison).
- Private clouds: private cloud (Jun 2025 comparison).
- Community clouds: community cloud (Dec 2024, Jun 2025).
- Hybrid clouds: hybrid cloud and deployment comparison (Dec 2024, Jun 2025).
- Advantages of Cloud computing: benefits; social networking (Dec 2024).
- Comparing cloud providers with traditional IT service providers: comparison points.