Overly on Security

About this Blog:

The legal side of security.

Michael Overly

Storm Clouds: Ensuring Data Availability in a Hosted Environment

|

With all the talk these days about cloud computing, SAAS, and ASPs, we see much focus on ensuring data entrusted to these vendors is adequately secured. This usually covers the first two letters in the well-known CIA acronym (i.e., Confidentiality, Integrity, and Availability), but the service levels for these vendors – the all important availability, response time, and other performance requirements – are frequently very thin. Given the recent, highly publicized downtime at several of the most well known vendors in this space, I thought it might be useful to highlight some of the key elements to be considered in drafting effective service levels agreements (SLAs):


1. SLAs should be clear and absolutely objective. The vendor should be required to provide monthly reports on SLA performance. 


2. Remedies (generally some form of credit) should be associated with each SLA. Remedies should escalate depending on the severity of the SLA failure (e.g., a 10% credit for availability between 99%-99.9 and a 20% credit for availability between 98%-99%). Repeated failures in a given time period should also cause escalation of remedies. All credits should be made automatically, without the need for the customer to request the remedy.


3. Repeated failures (e.g., two failures in any four month period) should, in addition to all other remedies under the contract, give the customer the right to terminate the agreement. Repeated failures should also require the vendor to provide a root cause analysis of the failures and a specific plan to minimize future performance issues.


4. Broad force majeure exceptions to SLA performance should be avoided. While general Internet and infrastructure failures may be excluded, events such as strikes, power failures, labor issues, accidents, etc. should not. In particular, if a circle is drawn around the vendor facility providing the service, anything that happens within that circle, regardless of whether it constitutes an Act of God or not, should not relieve the vendor of its SLA obligations. You are buying a service. If the vendor fails to provide that service for any reason, there should be an adjustment in fees (i.e., the credit remedy mentioned above).


5. Credits issued for SLA failures should not be framed in terms of “exclusive remedies.” The customer should have all other remedies available to it under the agreement, including the ability to declare a breach, terminate, and seek damages to compensate for poor performance. 


6. Include the ability for the parties to meet and confer on at least an annual basis to evaluate existing SLAs and discuss potential changes.

 

Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
WHITE PAPER
Reduce Email Archives up to 60%

Clearwell Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.

» Learn More

WHITE PAPER
Aberdeen Report: To Patch, or Not to Patch? (Not If, But How)

Secunia The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.

» Learn More

Browse CSO Blogs

See all CSO Blogs »

Recent Comments

RESOURCE CENTER