230 likes | 344 Views
Application Service Providers (ASPs) offer outsourced hosted applications for businesses, but trusting them with your data demands thorough scrutiny. This guide by Ian Poynter and Diana Kelley delves into the essentials of choosing an ASP, including security policies, application hosting designs, and contingency planning. It emphasizes critical questions customers should ask and highlights best practices for ASPs to ensure data security, compliance, and reliability. Equip yourself with the knowledge to safeguard your business data when partnering with an ASP.
E N D
The Truth About ASPs Trusting Strangers with Your Business Data
Introductions • Ian Poynter, Jerboa Inc. • ian@jerboa.com • Diana Kelley, LockStar, Inc. • dkelley@lockstar.com Ian Poynter & Diana Kelley
What is an ASP? • Application Service Provider • Outsourcing Taken to the Extreme • Hosted Applications • Hosted Business Data Ian Poynter & Diana Kelley
Examples • Contact Management • Agillion • Backups • Recovery Solutions Ian Poynter & Diana Kelley
Examples • Calendaring • eCal • Storage • iDrive Ian Poynter & Diana Kelley
Questions • For Customers • Questions to Ask • For ASPs • Questions to Answer Ian Poynter & Diana Kelley
Longevity • How Long Has the ASP Been in Business? • Who Are Their Other Customers? • What Do Their References Say? Ian Poynter & Diana Kelley
Security Policy • Is There a Security Policy? • How Do the ASP’s Procedures Reflect Their Policies? • How Are the Policies Upheld? • Customer Policies Should Be Willingly Accepted • Customer Suggestions Should Be Accepted Ian Poynter & Diana Kelley
Security Policy • How Does the ASP Ensure Their Policies Are Enforced? • Do They Conduct Audits? • Third-party “seals of approval” • Do They Keep Secure Logs? • Are There “Checks and Balances”? Ian Poynter & Diana Kelley
Application Hosting Design • What is the ASP’s Security Approach? • Philosophy and Strategy • Design and Implementation Ian Poynter & Diana Kelley
Application Hosting Design • Problems with Shared Servers • Data Confusion • Physical and Network Security • Is The Facility Secured? • Is The ASP Production Network Secure? • Consider Also Their Corporate Network Ian Poynter & Diana Kelley
Application Hosting Design • Home-grown vs. Custom Application • Is This Custom Software or SAP? Ian Poynter & Diana Kelley
COTS Applications • Can the ASP Get Security Problems Fixed? • Is the Software Vendor Responsive? • What Control Does the ASP Have? • How Reliable Is the Vendor? Ian Poynter & Diana Kelley
Home-Grown Applications • Are Applications Built With Security in Mind? • Not “Tacked On” • How Often Are Applications Modified? • Daily? Weekly? • Is There A Formal Quality Assurance Process? • Opportunities for Error Abound Ian Poynter & Diana Kelley
Code Reviews • Who Has Reviewed the ASP’s Code? • Probably No One • Problems with COTS Software • Was the Review Independent? • Or Was It Internal? • How Often Are Reviews Repeated? Ian Poynter & Diana Kelley
Contingency Planning • Disaster Recovery • Do They Do It? • Backups • Sent Off-site? • What Is the Off-site Backup Storage Policy? Ian Poynter & Diana Kelley
Contingency Planning • Incident Response • What Are the Policies and Procedures? • What Is the Escalation Path? • How Quickly Do I Find Out My Data Was Compromised? Ian Poynter & Diana Kelley
Availability • What Kind of Redundancy Is Built Into the Asp’s Systems? • What Guarantees of Availability Are There? • Uptimes? • MTBF Ian Poynter & Diana Kelley
Separation Safeguards • Data Separation • Is Customer Data Kept Separate? • Is Data Safe From Internal Threats? • Employees and Contractors • Who Has Access to Your Data? Ian Poynter & Diana Kelley
Employee Screening • How Experienced Are The Asp’s Employees? • Does the ASP Screen Their Employees? • Reference Checks? • Background Checks? Ian Poynter & Diana Kelley
What Should ASPs Do? • Cover Themselves • Get Insurance • Take Security Seriously • And Do It Well • Prepare to be Sued Ian Poynter & Diana Kelley
What Should ASPs Do? • Security As Marketing • Do All the Things We Describe • Take Security Seriously Ian Poynter & Diana Kelley
What Should Customers Do? • Ask the Hard Questions • Get Everything in Writing • Get Assurance from the ASP of • Availability • Coverage for Losses • Get Insurance Ian Poynter & Diana Kelley