Best security questions to ask about SaaS

By Ellen Messmer, Network World |  SaaS 1 comment

Security issues have to be clearly examined before diving into software as a service (SaaS), warns Burton Group analyst Eric Maiwald, who shed some light on the subject at this week's Infosec conference.

SaaS, offered via a cloud computing platform, can offer cost savings and speed in platform deployment in many instances, compared to a business trying to acquire and install software internally. Businesses eager to race into the cloud typically say "they can measure the cost savings the first couple of years," said Maiwald. "But I think they're leaving something out."

What's often missing is inclusion of the costs to conduct a suitable level of verification on the vendor, including security and legal reviews, data-center site visits and other practices necessary to ensure compliance obligations are met.

Beyond the hard cost considerations, there are myriad security questions any business should be asking, Maiwald said. These include:

- Which of the SaaS employees has root and database access, and will anything prevent them from getting access to your corporate data? What controls are in place?

- Is data held encrypted? How?

- Is the held data separated between clients or is it all stored on one huge database out there? How is data separated? How will the legal question of e-discovery be addressed should it arise as a business concern?

- Is the data flowing between the business and the vendor's cloud-computing infrastructure secured in some way?

- What controls would prevent vendor insiders from downloading your data onto a USB stick and walking out the door?

- In terms of service availability, can you get your vendor to sign a service-level agreement?

- Is their data center in a location prone to hurricanes or earthquakes? What are their back-up plans?

- What information is captured in audit logs?

- Are there ways to limit where SaaS vendors go within the corporate network?

Despite his critical remarks, Maiwald acknowledged in some instances SaaS and cloud computing vendors may offer better availability than their business clientele could achieve due to the investments vendors can make to scale up their services.

"Google, Microsoft, Amazon are doing amazing stuff with what they're putting into their data centers," he said.

He noted that a few years ago SaaS-styled vendors would be vague in discussing their security controls, but just recently at a forum with Salesforce.com, Qualys, IBM and others, he found vendors much more forthcoming than previously.

One aspect of SaaS to be mindful about is that vendors prefer to provide a common set of services in order to take advantage of scale, Maiwald pointed out. So that means "vendors may not be willing to change internal policies as their economies of scale will suffer," he said.

Maiwald added that technical controls, such as for content or rights management, typically don't work as well in an outsourced environment. When you entrust your data to SaaS, "audit replaces your day-to-day management controls and technical controls," he asserts, adding contracts have to carefully crafted, something IT people will need a lot of help in from legal staff.

Many businesses may want to ask if the SaaS vendor they're considering has passed a so-called "SAS 70" audit, Maiwald said. There are two types of SAS-70 audits, he points out, and Type 2 is much more stringent.

The larger question of how SaaS may impact the business in general can't be ignored since companies may be sacrificing IT skills and competence when they choose SaaS. Maiwald said his basic recommendation would be to limit the number of SaaS vendors to a few strategic partners.

1 comment

    Anonymous 2 years ago
    You have listed out some very important security considerations. We had done a similar article earlier, listing out factors other than security, that should considered while selecting a SaaS vendor. It is true that companies have a lot of concerns before adopting SaaS, and most of these are valid, and must be allayed before a customer selects a SaaS solution. You can find our article at - http://www.hyperoffice.com/saas-reviews-for-smbs/

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SaaSWhite Papers & Webcasts

      White Paper

      The Journey to the Private Cloud

      Both business and IT need the agility enabled by the private cloud. Now you can apply technologies and processes pioneered by public cloud services to your own data center.

      Webcast On Demand

      Navigating the Public Cloud

      InfoWorld contributing editor and consultant David Linthicum offers expert advice about choosing services to outsource to the public cloud providers, cloud data security and identity, integrating public cloud services, and how to avoid provider lock-in.

      Sponsor: Intel

      White Paper

      Moving Service Management to SaaS

      Today, organizations can enjoy similarly substantial benefi ts by migrating their IT service management functions to a software-as-a-service model. This paper shows how Nimsoft Service Desk enables organizations to make the most of this opportunity.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question