IaaS Service Catalog: What It Is and Why Governance Fails
In short
An IaaS service catalog is a curated list of cloud infrastructure services available to users, but inconsistent governance and lifecycle management are where most implementations stumble.
An IaaS service catalog is a structured inventory of cloud infrastructure services, such as virtual machines, storage, and networking components, that an organisation makes available to internal teams or external customers. Its purpose is to standardise provisioning, enforce compliance, and control costs, but in practice, most failures stem from weak governance, poor lifecycle management, and misalignment with enterprise architecture frameworks.
The Role of the IaaS Service Catalog
In a cloud environment, the service catalog acts as a bridge between infrastructure providers and consumers. It defines what services are available, their configurations, pricing, compliance status, and access controls. For example, a catalog might list approved VM sizes for production workloads, each with predefined security groups, backup policies, and tagging requirements.
This approach supports self-service provisioning while maintaining control. Without a catalog, teams often provision resources ad hoc, leading to sprawl, security gaps, and unauthorised costs. A well-maintained catalog ensures that only approved, compliant, and optimised configurations are deployed.
The catalog is central to frameworks like TOGAF, particularly in the Technology Architecture domain, where standardisation and reuse are core principles. It also supports ITIL Service Portfolio Management by treating infrastructure as a service offering with defined SLAs, costs, and lifecycle stages.
Where Practitioners Struggle
Despite its conceptual clarity, implementing and maintaining an IaaS service catalog is where most organisations encounter difficulties. The technical setup is often straightforward, but governance and adoption are persistent challenges.
1. Lack of ownership and governance
One of the most common issues is unclear ownership. Is the catalog managed by cloud operations, security, architecture, or finance? Without a designated steward, updates lag, deprecated services remain listed, and compliance drifts.
Teams may bypass the catalog entirely if it doesn’t meet their needs, creating shadow IT. For example, if the catalog doesn’t offer a specific GPU instance type, developers may provision it directly through the cloud provider’s console, undermining governance.
A governance board, comprising representatives from infrastructure, security, and business units, is essential to review new service requests, deprecate outdated offerings, and enforce compliance policies.
2. Inconsistent lifecycle management
Services in the catalog must have defined lifecycles: introduction, active, maintenance, and retirement. Yet many organisations fail to enforce deprecation schedules.
An outdated VM image with unpatched vulnerabilities might remain in the catalog because no one owns its removal. This creates security risks and complicates audits. Regular reviews, automated alerts, and integration with patch management systems are necessary to maintain catalog hygiene.
3. Misalignment with security and compliance frameworks
The catalog must reflect current compliance requirements, such as data residency, encryption standards, and access controls. However, many implementations treat the catalog as a technical inventory rather than a compliance enforcement tool.
For instance, a storage service might be listed without indicating whether it meets NIST SP 800-53 controls for data protection or if it’s certified under ISO 27001. This forces teams to investigate compliance separately, defeating the purpose of the catalog.
Integrating compliance checks directly into service definitions, such as tagging resources with control mappings or embedding audit trails, ensures that every provisioning action is policy-aware.
4. Poor user experience and adoption
Even the most comprehensive catalog fails if users don’t adopt it. A common mistake is designing the catalog from a technical perspective rather than a user one. If finding and provisioning a service requires navigating complex menus or submitting multiple approvals, teams will look for shortcuts.
Successful catalogs prioritise usability: clear descriptions, search functionality, role-based visibility, and integration with CI/CD pipelines. They also provide feedback, such as cost estimates and compliance status, during provisioning to guide decision-making.
Building a Sustainable Catalog
To avoid these pitfalls, organisations should:
- Assign clear ownership and establish a governance process for service lifecycle management.
- Integrate the catalog with identity and access management (IAM) to enforce role-based access.
- Automate compliance checks using policy-as-code tools (e.g., HashiCorp Sentinel, Open Policy Agent).
- Regularly audit the catalog for accuracy, security, and usage patterns.
- Align service definitions with enterprise architecture standards and regulatory requirements.
The catalog should not be a static document but a living component of the cloud operating model, one that evolves with business needs and regulatory changes.
For practitioners aiming to strengthen compliance in cloud service governance, the COBIT 2019 Governance Implementation Playbook for Telecommunications Service Providers offers a structured approach to aligning service catalogs with enterprise governance, risk, and compliance objectives, even beyond the telecom sector.
Questions people ask about this
What does this article cover?
Who should read this cloud & infrastructure article?
How can I apply these cloud & infrastructure insights?
Explore this topic on our compliance platform
Our platform covers 704 compliance frameworks with 307K+ verified cross-framework control mappings. Start free, no credit card required.
Try the Platform Free →