questions you should be asking your cloud service provider

19
Questions You Should Be Asking Your Cloud Service Provider Jamie Tischart| CTO Cloud | SaaS, Intel Security

Upload: mcafee

Post on 10-Apr-2017

1.620 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Questions You Should Be Asking Your Cloud Service Provider

Questions You Should Be Asking Your Cloud Service ProviderJamie Tischart| CTO Cloud | SaaS, Intel Security

Page 2: Questions You Should Be Asking Your Cloud Service Provider

2

When Vetting a Cloud Service or SaaS Provider

Don’t make assumptions on what security is and isn’t included.

Perform in-depth reviews of the terms & conditions.

Each service will usually have different T&C’s, so review them all.

Find out how they handle data security and

privacy.

Page 3: Questions You Should Be Asking Your Cloud Service Provider

3

Security Questions

Page 4: Questions You Should Be Asking Your Cloud Service Provider

4

Do you outsource any of your

data storage?

Who has access to my data, both physically and virtually?

Page 5: Questions You Should Be Asking Your Cloud Service Provider

5

How do you handle legal

requests for data review?

Page 6: Questions You Should Be Asking Your Cloud Service Provider

6

What is your data architecture, and how is my data isolated from your other customers?

How and when is my data

deleted?

Page 7: Questions You Should Be Asking Your Cloud Service Provider

7

What certifications and

| or third-party audits are

performed on your service?

Page 8: Questions You Should Be Asking Your Cloud Service Provider

8

Privacy Questions

Page 9: Questions You Should Be Asking Your Cloud Service Provider

9

What data do you collect from my

organization, and how is it kept

private?

What is that data used for?

Page 10: Questions You Should Be Asking Your Cloud Service Provider

10

How long do you retain that

data?

Page 11: Questions You Should Be Asking Your Cloud Service Provider

11

Do you encrypt the data in any manner?

Where is the data

stored?

Page 12: Questions You Should Be Asking Your Cloud Service Provider

12

Do you roll up data and transmit it to other internal or

external entities, and if so,

how is it transmitted and to where?

Page 13: Questions You Should Be Asking Your Cloud Service Provider

13

Operational Questions

Page 14: Questions You Should Be Asking Your Cloud Service Provider

14

What is your database and

storage architecture redundancy

model?

What is your backup frequency?

Page 15: Questions You Should Be Asking Your Cloud Service Provider

15

What is the recovery time

from failure: minimum,

average, and maximum?

How can I access or download my data from your service?

Page 16: Questions You Should Be Asking Your Cloud Service Provider

16

Do you provide any analytic tools for my data?

In the event of data

corruption, what is the maximum data loss that I can

expect?

Page 17: Questions You Should Be Asking Your Cloud Service Provider

17

Conclusions• Do the groundwork. Review all of

your contracts. • If guarantees and offers are not clear,

ask for clarification.

• Be sure to know the security, privacy and operational practices and guarantees.

Page 19: Questions You Should Be Asking Your Cloud Service Provider