Miscellaneous

Business Blogs - Blog Rankings

« Intellectual Property Theft Alleged in China | Main | Intellectual Property Theft - Goldman Sachs »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a01156fbeecf2970c0115719d7bfd970b

Listed below are links to weblogs that reference Cloud Computing Security:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

The reality in establishing effective agreements with Managed Service Providers(MSP) is it is almost never ideal for you to insist that the MSP implement your particular set of IT General Controls. (Key: Who's Responsibility is IT? - At the end-of-the-day you report to your shareholders.

First you need to define your own internal set of policies and procedures and convey those requirements to the MSP.

Second, you need to confirm their stated policies and procedures in relation to your own internal requirements, prior to an agreement.

The Third step is that you MUST BE ABLE to audit theirs, and have the authority to do so on an ongoing basis.

The Final condition prior to signing is that they assume some type of risk related penalties(i.e. "Quantifiable Metrics"

I strongly recommend that you ensure within your SLA that you actually have the necessary authority for you(or a designated 3rd party) to audit their internal policies and procedures.

If you don't, I would insist that you have made an insufficient arrangement on behalf of your organization.

P.S. Always include RISK as a key factor in evaluating IT Outsourcing!

Christopher Peterson
Mainstream Networks Ltd.
Vancouver, BC
www.mainstreamnetworks.ca

Christopher,

Thank you for your post. I wholeheartedly agree with your comments on being able to audit. Without audit provisions, you will never be in a position to understand what is happening with your managed service provider and won't be able to effectively ensure the management of your information risks.

When establishing audit provisions, you must clearly articulate the details that will ensure you have adequate access to the managed service providers staff, technical environment, documentation, and processes. I would also add within the audit provisions the ability to change the provisions to address either previously unknown risks or new risks that emerge.

Audit provisions can also help a company renegotiate SLA elements in the future, because conducting audits can provide critical data to support requests for service level changes from the managed service provider.

Ultimately, effective audit provisions and their execution, will help ensure that you have the necessary knowledge and understanding over time to drive actions by the service provider to managed information risk.


Mark Brooks

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

Connect w/Mark