the truth about asps

23
The Truth About ASPs Trusting Strangers with Your Business Data

Upload: marisa

Post on 07-Jan-2016

32 views

Category:

Documents


0 download

DESCRIPTION

The Truth About ASPs. Trusting Strangers with Your Business Data. Introductions. Ian Poynter, Jerboa Inc. [email protected] Diana Kelley, LockStar, Inc. [email protected]. What is an ASP?. Application Service Provider Outsourcing Taken to the Extreme Hosted Applications - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: The Truth About ASPs

The Truth About ASPs

Trusting Strangers with Your Business Data

Page 2: The Truth About ASPs

Ian Poynter & Diana Kelley 2

Introductions

Ian Poynter, Jerboa Inc. [email protected]

Diana Kelley, LockStar, [email protected]

Page 3: The Truth About ASPs

Ian Poynter & Diana Kelley 3

What is an ASP?

Application Service Provider

Outsourcing Taken to the Extreme

Hosted ApplicationsHosted Business Data

Page 4: The Truth About ASPs

Ian Poynter & Diana Kelley 4

Examples

Contact ManagementAgillion

BackupsRecovery Solutions

Page 5: The Truth About ASPs

Ian Poynter & Diana Kelley 5

Examples

CalendaringeCal

Storage iDrive

Page 6: The Truth About ASPs

Ian Poynter & Diana Kelley 6

Questions

For CustomersQuestions to Ask

For ASPsQuestions to Answer

Page 7: The Truth About ASPs

Ian Poynter & Diana Kelley 7

Longevity

How Long Has the ASP Been in Business?Who Are Their Other Customers?

What Do Their References Say?

Page 8: The Truth About ASPs

Ian Poynter & Diana Kelley 8

Security Policy

Is There a Security Policy?

How Do the ASP’s Procedures Reflect Their Policies?

How Are the Policies Upheld?Customer Policies Should Be Willingly

Accepted

Customer Suggestions Should Be Accepted

Page 9: The Truth About ASPs

Ian Poynter & Diana Kelley 9

Security Policy

How Does the ASP Ensure Their Policies Are Enforced?Do They Conduct Audits?

Third-party “seals of approval”

Do They Keep Secure Logs?

Are There “Checks and Balances”?

Page 10: The Truth About ASPs

Ian Poynter & Diana Kelley 10

Application Hosting Design

What is the ASP’s Security Approach?Philosophy and Strategy

Design and Implementation

Page 11: The Truth About ASPs

Ian Poynter & Diana Kelley 11

Application Hosting Design

Problems with Shared ServersData Confusion

Physical and Network Security Is The Facility Secured?

Is The ASP Production Network Secure?Consider Also Their Corporate Network

Page 12: The Truth About ASPs

Ian Poynter & Diana Kelley 12

Application Hosting Design

Home-grown vs. Custom Application Is This Custom Software or SAP?

Page 13: The Truth About ASPs

Ian Poynter & Diana Kelley 13

COTS Applications

Can the ASP Get Security Problems Fixed?

Is the Software Vendor Responsive?What Control Does the ASP Have?

How Reliable Is the Vendor?

Page 14: The Truth About ASPs

Ian Poynter & Diana Kelley 14

Home-Grown Applications

Are Applications Built With Security in Mind?Not “Tacked On”

How Often Are Applications Modified?Daily? Weekly?

Is There A Formal Quality Assurance Process?

Opportunities for Error Abound

Page 15: The Truth About ASPs

Ian Poynter & Diana Kelley 15

Code Reviews

Who Has Reviewed the ASP’s Code?Probably No One

Problems with COTS Software

Was the Review Independent?Or Was It Internal?

How Often Are Reviews Repeated?

Page 16: The Truth About ASPs

Ian Poynter & Diana Kelley 16

Contingency Planning

Disaster RecoveryDo They Do It?

BackupsSent Off-site?

What Is the Off-site Backup Storage Policy?

Page 17: The Truth About ASPs

Ian Poynter & Diana Kelley 17

Contingency Planning

Incident ResponseWhat Are the Policies and Procedures?

What Is the Escalation Path?How Quickly Do I Find Out My Data Was

Compromised?

Page 18: The Truth About ASPs

Ian Poynter & Diana Kelley 18

Availability

What Kind of Redundancy Is Built Into the Asp’s Systems?

What Guarantees of Availability Are There?Uptimes?

MTBF

Page 19: The Truth About ASPs

Ian Poynter & Diana Kelley 19

Separation Safeguards

Data Separation Is Customer Data Kept Separate?

Is Data Safe From Internal Threats?Employees and Contractors

Who Has Access to Your Data?

Page 20: The Truth About ASPs

Ian Poynter & Diana Kelley 20

Employee Screening

How Experienced Are The Asp’s Employees?

Does the ASP Screen Their Employees?Reference Checks?

Background Checks?

Page 21: The Truth About ASPs

Ian Poynter & Diana Kelley 21

What Should ASPs Do?

Cover ThemselvesGet Insurance

Take Security SeriouslyAnd Do It Well

Prepare to be Sued

Page 22: The Truth About ASPs

Ian Poynter & Diana Kelley 22

What Should ASPs Do?

Security As MarketingDo All the Things We Describe

Take Security Seriously

Page 23: The Truth About ASPs

Ian Poynter & Diana Kelley 23

What Should Customers Do?

Ask the Hard Questions

Get Everything in Writing

Get Assurance from the ASP ofAvailability

Coverage for Losses

Get Insurance