Six Questions to Ask Before Joining the Cloud

It's ultimately your data, and you can't always count on an SLA to keep it safe and available.

By  Sue Poremba | Jun 16, 2010
Print ArticleEmail Article
  • Share on Facebook
  • Share on Twitter
  • Share on LinkedIn

Data Loss

1 | 2 | 3 | 4 | 5 | 6
Previous Next

You need to ask your cloud service provider what its data-protection policy is and what its audit procedures are. And then you should perform due diligence on those procedures.

It's vital to employ a carefully defined risk analysis of IT systems and procedures before deciding which cloud technology and service is best for your organization, writes Cyber-Ark VP Adam Bosnian in "Cloud Computing: Understanding the Risks and Questions to Ask Your Service Provider.� That analysis must be done before starting later steps such as creating service level agreements, remediation procedures and penalty clauses. 

The four main stages in this analysis are as follows:

ID management and access control Who is authorized to do what and when?

Regulatory requirements – Basel II, SOX, PCI, SAS70.

Data-handling processes Where is the company's data located? And how is it managed?

Staff management What happens when someone leaves, comes on board or changes roles?

While cloud computing changes the data-handling ballgame significantly, the gap between network and cloud-based security analyses is not as great as some experts report it to be. (That is provided the IT security technology being employed or planned by the organization can handle cloud, as well as conventional, IT data-storage systems.) It's necessary to assess the expectations that management and the business have for the cloud outsourcing contract. What precise functions must the outsourcing company complete? And to what performance and security criteria will that provider be held? The six questions Bosnian recommends are ideal for IT departments moving toward their first contract with a cloud provider. And be sure to read Adam's full article, which elaborates on the answers that the IT department needs to be comfortable with before negotiating a final contract with a provider.

Comment and Contribute
(Maximum characters: 1200). You have
characters left.
Get the Latest Scoop with Enterprise Networking Planet Newsletter
Helpful Links
  • Yankee Group Mobile WAN Optimization Report

    Mobile work continues to evolve. Your organization must keep up with the demands of its mobile workforce. This report introduces the concept of mobile WAN optimization and provides three case studies including RCM, PRTM and Einstein that highlight how this emerging technology can help IT departments achieve what previously appeared to be conflicting goals. Read >

  • Network Security Resources

    More threats than ever before pose a danger to today's enterprise network. Get the latest tips and intel on the newest risks in our guide to network security resources. Read >

  • Extreme Savings: Cutting Costs with WAN Optimization

    Did you know it's possible to cut IT costs without impacting day-to-day IT operations? In fact, when you download this whitepaper from Riverbed on cost-savings through WAN optimization, you'll discover how businesses of all different sizes have realized a return on investment in just a few months through significant hard cost savings in areas such as bandwidth reduction and IT consolidation. It's called Extreme Savings and its only from Riverbed. Read >