iTnews
  • Home
  • News
  • Technology
  • Networking

EU security agency issues cloud SLA checklist

By Liam Tung
Apr 4 2012 3:00PM
Follow google news

Guidance for public sector cloud procurement.

Europe's key security agency has released a cloud procurement checklist in a bid to improve how government organisations assess cloud computing contracts and services.

EU security agency issues cloud SLA checklist

According to the European Network and Information Security Agency (ENISA), public sector cloud adoption was hindered by a lack of relevant procurement methods, and not the maturity of cloud providers.

The guide, released this week, aims to address difficulties organisations face in ensuring service level agreements (SLAs) are met, monitored and reported.

It follows an earlier ENISA survey that found that government agencies received little feedback from providers about availability or security vulnerabilities of cloud services bought. 

ENISA’s 2011 survey of 117 public sector IT managers who struck cloud service contracts found that only 32 percent of contracts included ways to classify the severity of security incidents.

Only 15 percent of organisations actually received availability reports, seven percent received penetration testing reports, and 16 percent received back up reports. 

Only 44 percent of contracts imposed penalties on cloud providers that failed to meet their SLAs.

SLAs in Australia

The Australian Government appears ready to begin procurement discussions with cloud service providers after years of hesitation, releasing draft guidelines for low-value cloud computing deals last week.

According to an iTnews investigation of cloud SLAs in Australia, customers tend not to expect their service providers to meet the agreed levels of availability.

In an iTnews analysis of 25 standard cloud computing contracts, Truman Hoyle partner Mark Vincent warned against relying solely on SLAs to judge the reliability of a cloud vendor.

For Australian agencies, ENISA's guidance on identifying "security-relevant parameters", monitoring security features and sharing responsibilities between provider and customer may be useful.

The European agency also highlighted forensics, incident response expectations and severity classifications, elasticity and load tolerance testing, back up procedures, vulnerability management, change management and data isolation guidelines.

ENISA said the guide aimed to provide the public sector with tools to protect citizens.

“Europe’s citizens trust public and private sector bodies to keep our data secure," said professor Udo Helmbrecht, executive director of ENISA.

"With ever more organisations moving to cloud computing, ENISA’s new guidance is well-timed to help give direction in what is, for many buyers, a completely new area."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cloudcoverenisafeedbacknetworkingpenaltyprocurementsecurityslasoftwarestoragetransparency

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
AI is delivering business value today
Partner Content AI is delivering business value today
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Group to expand RFID tagging to more products and to Target

Kmart Group to expand RFID tagging to more products and to Target

Federal Parliamentary Computer Network set for its "most significant" upgrade

Federal Parliamentary Computer Network set for its "most significant" upgrade

WA man jailed for at least five years for evil twin attack

WA man jailed for at least five years for evil twin attack

Optus fast-tracks network operations insourcing from Nokia

Optus fast-tracks network operations insourcing from Nokia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.