What is cloud storage?¶
Cloud storage is a service that keeps files or other data on provider-controlled systems and makes them available over a network.
The user may access the data through a browser, mobile application, desktop synchronisation tool or another connected service.
What this means in practice¶
A cloud-storage service may manage file versions, sharing, permissions, deleted items, previews, synchronisation and access logs. It may also create local copies or placeholders on several devices.
The same file may therefore exist in different forms. There may be a live cloud copy, older versions, downloaded copies, cached previews, synced device copies and backups.
Cloud storage may be personal or organisational. In a business environment, the organisation may control the tenant, policies and audit records even though individual users create and edit files.
Also establish whether the file was uploaded manually, synchronised automatically, created by an application or copied from another user.
The provider may hold server-side records that are not visible in the ordinary user interface. The customer organisation may hold separate audit or administrative records.
What this may show¶
Investigators should identify the service, account or tenant, file identifier, owner, sharing settings, version history, relevant timestamps and linked devices.
What this does not show on its own¶
The dangerous assumption is that cloud storage is simply an external hard drive.
A file appearing in cloud storage does not prove who created it, who viewed it or whether it was ever fully downloaded to a device.
What to do next¶
Do not describe a file merely as “found in the cloud”. Record the precise service, folder, account, export and acquisition method.
Key takeaway
Cloud storage is an active service with versions, sharing and synchronisation, so examine the file’s history and access context rather than treating it as a single remote copy.