Скачиваний:
50
Добавлен:
20.06.2019
Размер:
50.48 Mб
Скачать

14  Cloud Compliance: A Framework for Using Cloud Computing in a Regulated World

253

14.2.5.6  Service Level Agreements

It is also expected that the client organization will be entitled to a bare minimum level of service. It is incumbent on the client to demand relevant, measurable, and specific Service Level Agreements (SLAs) and Service Level Objectives (SLOs) for security-related events, although the client must be aware that there is an inverse relationship with the timeliness of response for most issues and the cost of the service given. This initiative should be linked to the Business Impact Assessment results as well.

14.2.6  Other Considerations

Some of the other considerations to give thought to involve ensuring that the cloud providers have an appropriate governance structure with clearly defined problemmanagement procedures and escalation paths. Some other key procedures and plans should also be included, such as incident response plans with appropriate roles and responsibilities outlined for both the client and the provider.

14.2.6.1  Disaster Recovery/Business Continuity

An organization needs to be adequately satisfied with the ability of the cloud provider to ensure appropriate availability of the client’s corporate assets with which they were entrusted. It may be suggested that the client be privy to reviews of the business continuity plans or disaster recovery plans, or related testing activities. Again, verbiage around this concept should be captured within the contract to ensure suitability and appropriate compensation are considered.

14.2.6.2  Governance Structure

As stated previously, the cloud provider’s governance structure should be investigated and arrangements with respect to communication should be formalized. This is required specifically around escalations and problem management, where an official channel needs to be established such that there is always an individual accountable and responsible on both the client and cloud provider sides to ensure adequate completion of the required tasks in a timely and acceptable fashion. There should always be an appropriate escalation point as well, in the event that the responsible individual is unable to complete the necessary tasks as outlined. The governance structure which would outline all of these, amongst many other processes, needs to be formalized and agreed upon prior to contract signing.

Соседние файлы в папке CLOUD COMPUTING