230 likes | 340 Views
The Truth About ASPs. Trusting Strangers with Your Business Data. Introductions. Ian Poynter, Jerboa Inc. ian@jerboa.com Diana Kelley, LockStar, Inc. dkelley@lockstar.com. What is an ASP?. Application Service Provider Outsourcing Taken to the Extreme Hosted Applications
E N D
The Truth About ASPs Trusting Strangers with Your Business Data
Introductions • Ian Poynter, Jerboa Inc. • ian@jerboa.com • Diana Kelley, LockStar, Inc. • dkelley@lockstar.com Ian Poynter & Diana Kelley
What is an ASP? • Application Service Provider • Outsourcing Taken to the Extreme • Hosted Applications • Hosted Business Data Ian Poynter & Diana Kelley
Examples • Contact Management • Agillion • Backups • Recovery Solutions Ian Poynter & Diana Kelley
Examples • Calendaring • eCal • Storage • iDrive Ian Poynter & Diana Kelley
Questions • For Customers • Questions to Ask • For ASPs • Questions to Answer Ian Poynter & Diana Kelley
Longevity • How Long Has the ASP Been in Business? • Who Are Their Other Customers? • What Do Their References Say? Ian Poynter & Diana Kelley
Security Policy • Is There a Security Policy? • How Do the ASP’s Procedures Reflect Their Policies? • How Are the Policies Upheld? • Customer Policies Should Be Willingly Accepted • Customer Suggestions Should Be Accepted Ian Poynter & Diana Kelley
Security Policy • How Does the ASP Ensure Their Policies Are Enforced? • Do They Conduct Audits? • Third-party “seals of approval” • Do They Keep Secure Logs? • Are There “Checks and Balances”? Ian Poynter & Diana Kelley
Application Hosting Design • What is the ASP’s Security Approach? • Philosophy and Strategy • Design and Implementation Ian Poynter & Diana Kelley
Application Hosting Design • Problems with Shared Servers • Data Confusion • Physical and Network Security • Is The Facility Secured? • Is The ASP Production Network Secure? • Consider Also Their Corporate Network Ian Poynter & Diana Kelley
Application Hosting Design • Home-grown vs. Custom Application • Is This Custom Software or SAP? Ian Poynter & Diana Kelley
COTS Applications • Can the ASP Get Security Problems Fixed? • Is the Software Vendor Responsive? • What Control Does the ASP Have? • How Reliable Is the Vendor? Ian Poynter & Diana Kelley
Home-Grown Applications • Are Applications Built With Security in Mind? • Not “Tacked On” • How Often Are Applications Modified? • Daily? Weekly? • Is There A Formal Quality Assurance Process? • Opportunities for Error Abound Ian Poynter & Diana Kelley
Code Reviews • Who Has Reviewed the ASP’s Code? • Probably No One • Problems with COTS Software • Was the Review Independent? • Or Was It Internal? • How Often Are Reviews Repeated? Ian Poynter & Diana Kelley
Contingency Planning • Disaster Recovery • Do They Do It? • Backups • Sent Off-site? • What Is the Off-site Backup Storage Policy? Ian Poynter & Diana Kelley
Contingency Planning • Incident Response • What Are the Policies and Procedures? • What Is the Escalation Path? • How Quickly Do I Find Out My Data Was Compromised? Ian Poynter & Diana Kelley
Availability • What Kind of Redundancy Is Built Into the Asp’s Systems? • What Guarantees of Availability Are There? • Uptimes? • MTBF Ian Poynter & Diana Kelley
Separation Safeguards • Data Separation • Is Customer Data Kept Separate? • Is Data Safe From Internal Threats? • Employees and Contractors • Who Has Access to Your Data? Ian Poynter & Diana Kelley
Employee Screening • How Experienced Are The Asp’s Employees? • Does the ASP Screen Their Employees? • Reference Checks? • Background Checks? Ian Poynter & Diana Kelley
What Should ASPs Do? • Cover Themselves • Get Insurance • Take Security Seriously • And Do It Well • Prepare to be Sued Ian Poynter & Diana Kelley
What Should ASPs Do? • Security As Marketing • Do All the Things We Describe • Take Security Seriously Ian Poynter & Diana Kelley
What Should Customers Do? • Ask the Hard Questions • Get Everything in Writing • Get Assurance from the ASP of • Availability • Coverage for Losses • Get Insurance Ian Poynter & Diana Kelley