« Cross-Device-Type Log Management vs Device-Specific Log Management | Main | Logging Poll #8 Analysis: Essential Log Context »
Companies should hold their outsourcer to the same high standards for internal control as they apply in-house. It starts with accountability – if you monitor the actions of privileged users they are less likely to transgress. And if they do, the outsourcer can take immediate action. It is no wonder that the credit card companies have made access to credit card holder data a cornerstone of their standard. Perhaps outsourcers should do the same when it comes to access to customer data?
What happens when an employee leaves the company and you expect he may have downloaded some customer data onto his private laptop before you de-provisioned him from the on demand sales management system? Can you call your provider and ask for the audit trail that proves or disproves his (or her) transgression? It certainly is a fair question to ask of your outsourced provider and the answer may surprise you. Shared services can be difficult to investigate, because in some cases logging and data may be stored on shared servers.
Reliability and 24/7 uptime are cornerstones of outsourced services. Customers should demand service-level agreement guarantees and on demand providers should put in place scalable and repeatable models to ensure they meet these service-level agreements. The requirements for pro-active monitoring of performance bottlenecks and speedy recovery if availability is at stake are mission critical. Putting log data in the hands of front-line service desk employees can dramatically speed up this process.
At the end of the day, customers should demand to know what risk mitigation their cloud providers is putting in place to protect data, support investigations and maintain service level agreements. It is no more than reasonable for customers to demand monthly reports that demonstrate control and accountability on the part of the service provider. Wouldn’t it be cool to see a report on who accessed your most critical data each month and to know that a service provider employee has reviewed this report on a daily basis? For cloud service providers executive reporting on security and availability risk mitigation could be an important differentiation.
Posted June 05, 2008 in | Permalink
TrackBack URL for this entry:
http://www.loglogic.com/mt/mt-tb.cgi/342
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | 7 |
| 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| 15 | 16 | 17 | 18 | 19 | 20 | 21 |
| 22 | 23 | 24 | 25 | 26 | 27 | 28 |
| 29 | 30 |