- • Understand and assess the Security Model/Architecture of Cloud Provider (Application, Network, Hypervisor, end-point and Data Security capabilities)
- • Ask the right questions and evaluate answers to assess the efficiency of their security control implementation
- • Assess the risk of adopting cloud services
|
- • Negotiate service availability, reliability and performance SLA’s
- • Assist with contractual security language:
- -Liability conditions, consequences & recourse for negotiated SLA
- -Exit Strategies, Data Recovery & mitigating vendor lock-in
- -Intellectual property agreements for negotiated SLA
- -Data Location requirements
- -Regulatory Compliance requirements
- • Review terms of contract and cloud provider’s standard contract clauses
|
- • New and Updated cloud specific security policies and procedures
- • Leveraging Govt-wide security requirements (tailoring of NIST SP 800-53 controls for cloud systems) and further tailoring it for any Agency specific needs
- • Reviewing vendor’s security assessment packages
- • Performing continuous monitoring of vendor’s security posture/controls
|