When there's a third party in the cloud
A third party can increase risk, so your contract should address this possibility
Computerworld - When contracting for cloud-computing services, one challenge is that there may be more parties involved than your company and the cloud vendor. The vendor might outsource some of the services covered in the contract, or it could end up under different ownership after a merger or acquisition. On the client end, you might choose to work with a cloud broker. Because the introduction of third parties can increase risk, it's essential for potential cloud clients to identify third parties before adopting a cloud service, thoroughly understand their roles and ensure that their responsibilities are effectively addressed in the contract.
Outsourcing
You need to know whether your cloud-computing vendor is itself outsourcing to another cloud-computing vendor. For example, a SaaS vendor, such as Dropbox, could be running its service in the data center of a third-party IaaS vendor, such as Amazon Web Services. This can increase the complexity of a cloud-computing contract, especially in determining which vendor is responsible for which action. To mitigate risk, the contract should obligate the cloud vendor to do the following:
* Identify any functionality that is outsourced and name the third party.
* Require any third-party vendor to abide by the same security policies and procedures that apply to the cloud vendor's employees.
* Have business continuity plans in the event that the third-party vendor fails.
* Take direct responsibility for all aspects of complying with the terms of its contract with you.
Mergers and acquisitions
In the past 12 months alone, the rate of cloud vendor acquisitions has been nothing short of breathtaking. Oracle purchased Right Now. SAP picked up Success Factors. Microsoft bought both Skype and Yammer. And that's just the tip of the iceberg. The risk for clients is that the new owner might not continue with the same product road map or honor contract terms.
No matter how good your due diligence ahead of signing a cloud contract, none of us can predict the future. Because cloud computing is a growing and volatile market, it has many new players. The weaker among them might not have long-term viability, while the stronger ones could become targets for acquisition. In either event, your data and ongoing access to the service could be at risk, so it is important to do what you can to mitigate these risks. One approach is to include contract language along these lines:
ASSIGNMENT. This Agreement shall be binding on the parties and their successors (through merger, acquisition or other process) and permitted assigns. Neither party may assign, delegate or otherwise transfer its obligations or rights under this Agreement to a Third Party without the prior written consent of the other party.
Other columns by Thomas Trappler
- Does your cloud vendor protect your rights?
- Software licensing in the cloud
- For credit card handlers, cloud computing guidelines just got clearer
- Regulations and the cloud: HIPAA modification provides clarity
- Certification programs are making it easier to know all about a cloud vendor
- The do's and don'ts of safeguarding cloud-based data with encryption
- For a good cloud contract, start with an RFP
- It takes a team to create a good cloud contract
- Cloud adviser: Contract for functionality, not a brand
- When there's a third party in the cloud
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- The Total Cost of Email In this white paper, we'll explore the true costs of fragmented email management and uncover how to reduce those costs with a cloud-based...
- Best Practices for Cloud-based Information Governance This paper explores the latest ideas on evaluating cloud deployment: public or private clouds, data location and privacy, data ownership and access, and...
- Manage Virtualized and Cloud Environments and the New Software-defined Data Center Analyst report by Enterprise Management Associates on the newly announced EMC Service Assurance Suite, and how well it addresses operational challenges and market...
- Reduction in deployment time of a service development environment at GMO Media using a private cloud Read this case study to learn how GMO Media achieved a significant reduction in the implementation period of a service development environment using...
- B2B Integration on Cloud: Real World Solutions and Technology Advances Watch the webcast with IBM experts to learn about the advancing capabilities and strategic direction for B2B Integration on Cloud.
- How The Cloud Threatens Midsize Enterprises...And What To Do About It A recent study showed 92% of IT pros recognize that moving to the cloud provides a competitive edge, but only 20% plan to... All Cloud Computing White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...
