Standard solution: evaluating a new cloud provider
From data type to tested exit plan
§Clarify the need
- 01Which service model suits the task — IaaS, PaaS or SaaS?
- 02What data must the service handle — do they contain personal data or other sensitive information?
- 03How critical is the service if it is down or data is lost?
- 04Is a public, private or hybrid cloud most appropriate for the task?
§Check the agreement
- 01Is there a data processor agreement in place if the vendor processes personal data?
- 02Where the data physically lies, and which countries the agreement applies to?
- 03What does the service level agreement (SLA) promise about uptime and response times?
- 04What is the supplier's responsibility, and what is your own responsibility under the shared responsibility model?
§Safety and exit
- 01Does the service support two-factor login and data encryption both at rest and in transit?
- 02Can data be exported in a usable format if you change supplier?
- 03What happens with the data if the agreement is terminated — are they deleted, and within what deadline?
- 04Is there a plan for how the service is replaced temporarily if the vendor fails?