So here are a few criteria for evaluation of SAAS vendors as a series of questions:
* have security requirements from legislation (e.g. Privacy act), regulation (e.g. PCI-DSS )and relevant best practice (e.g. ISO 27002 )been recorded?
*has a security architecture been developed, that considers both application and hosting infrastructure?
*does the application security architecture leverage the security functionality available in the application development framework?
*have security controls been tested functionally?
*has static code analysis for common security vulnerabilities been performed?
*has security functionality in framework been implemented?
*have security controls been tested for vulnerabilities by a qualified 3rd party?
*are release, change and configuration management processes in place?
About Me
- Matthew Hackling
- Matt runs his own security consultancy called Ronin Security. His focus is information security management and he has a keen interest in infrastructure and web application security. He's a CISSP and the current Branch Executive of the Melbourne chapter of the Australian Information Security Association.
Blog Archive
Labels
- AISA (1)
- australian information security market (1)
- career advice (1)
- causes (1)
- DoS (1)
- economics (1)
- FUD (1)
- futurism (1)
- information security governance (4)
- IPS (1)
- privacy (2)
- sacred cows (1)
- security patching (1)
- vulnerability management (1)
- webappsec (1)
Monday, October 5, 2009
Criteria for evaluating a cloud services provider
Was having some ideas about how cloud services providers could turn their investment in security into a compettitive advantage. For this to be accomplished there needs to be a frame of reference established.
Subscribe to:
Post Comments (Atom)
Handy Links
Matt's list of blogs
-
-
-
TEDxMaui -- Hack Yourself First3 weeks ago
-
-
-
FedRAMP: It’s Here but Not Yet Here2 months ago
-
Bunraku V0.0.36 months ago
-
GoGrid Security Breach10 months ago
1 comments:
Watch this space:
http://www.darkreading.com/securityservices/security/government/showArticle.jhtml?articleID=221600333
- J.
Post a Comment