Ensuring Security in an Outsourcing Relationship Illinois

More organizations are outsourcing critical IT functions to third parties. At the same time, they are under strict mandates to maintain records, protect consumer privacy, and report data breaches -- mandates that significantly affect these outsourcing agreements.

Local Companies

Advanced System Designs
(309) 263-7944
100 Yordy
Morton, IL
Netneering LLC
(773) 655-9173
4827 N. Sheridan Rd.
Chicago, IL
Network Sentry
630 715 5662
PO Box 1234
Chicago, IL
Swift Technologies, Inc.
847-289-8339
920 Davis Rd
Elgin, IL
Network Sentry
224-330-7573
PO Box 123
Schaumburg, IL
CIAN, Inc.
(309) 691-3000
1717 Candletree Drive
Peoria, IL
Novanis Enterprise Solutions
(217) 698-0999
3161 W. White Oaks Drive
Springfield, IL
CIAN, Inc
309-691-3000
1717 W. Candletree Drive
Peoria, IL
FHS3 Tech Service
309-310-3576
30 Waterside Circle
Bloomington, IL
NETPLATFORM, Inc.
(309) 685-9700
2216 W. Altorfer Drive
Peoria, IL



By Tara Swords

More organizations are outsourcing critical IT functions to third parties. At the same time, they are under strict mandates to maintain records, protect consumer privacy, and report data breaches -- mandates that significantly affect these outsourcing agreements.

The benefits of outsourcing are understandable. If properly managed, outsourcers can help organizations focus on their own core competencies, cut costs, and get specialized help for a problem the enterprise can't solve with in-house resources. An April 2006 report from research firm Gartner, Inc., predicted that the outsourcing market will grow at a healthy rate of 7.3% from 2004 through 2009.

As enterprises outsource more data-related functions, they are simultaneously juggling a variety of regulations that govern what they can and can't do with their data. For example, California Senate Bill 1386, aimed at curtailing identity theft, requires any company that conducts business in California or has customers in the state to notify those customers if their electronic personal information is exposed through a security breach. The European Union (EU) Data Protection Directive has some very strict rules for the way companies collect, use, and process individuals' personal data in an EU country. Health care organizations must also comply with the Health Insurance Portability and Accountability Act (HIPAA), a complex piece of legislation that requires organizations to protect personal health information.

The problem with outsourcing data-related functions is that in the end, enterprises may still be held accountable for much of what the outsourcer does.

"You can't really transfer much of your liability," says Michael Rasmussen, vice president and analyst Forrester Research. "Nobody will accept liability A to Z in security."

To protect themselves in outsourcing arrangements, organizations need to specify exactly what the liabilities are for the outsourcer  in service-level agreements (SLAs). These agreements should include provisions to ensure that service providers are in compliance -- or limit the enterprise's liability in the event of noncompliance. Here are some strategies:

  • Ask for what you want  Negotiations almost never result in one party getting everything it wants. Before you begin, you need to know what points are non-negotiable and which are less critical. But don't start compromising before you sit down at the table. "Start the negotiation with what is the ideal situation for yourself. Then work with your business partner to define what's feasible," Rasmussen says.
  • Choose a jurisdiction  CIOs should understand that the service provider's home-country rules apply unless the contract names a different governing jurisdiction. For that reason, Rasmussen says, some organizations are building models that take different countries' laws into account. "Organizations will set up some type of framework, such as assigning level one through five depending on the intellectual property laws in a specific jurisdiction," he says. "That will govern what type of outsourcing relationships they'll allow in those jurisdictions."
  • Include an NDA Nondisclosure agreements, or NDAs, should require the service provider and its employees to agree that they will not disclose any sensitive information or intellectual property about your company to any other party. Detail exactly what kinds of information the NDA covers, and specify that the information cannot be communicated in any way: verbally, through email, over the phone, on paper, or in video, for example. Make the NDA both broad and specific.
  • Reserve the right to run background checks -- then do it  It sounds like a hassle, but a company should run background checks on all service provider employees who will have access to its information. According to a November 8, 2005, report from Gartner, Inc., "The United States Sentencing Commission Organizational Sentencing Guidelines require that personnel screening be done to make sure that access to information and processes is not given to individuals who have a history of criminal behavior." In other words, an enterprise may be at least partly liable if a service provider employee has a criminal record and discloses or misuses the enterprise's data.
  • Negotiate to prevent problems  It's almost impossible to put a dollar amount on brand or reputation damage. For example, if a service provider sells sensitive customer data to identity thieves posing as a legitimate business, the enterprise must work to rebuild trust with customers -- an immeasurable task. That's why it's important to structure contracts in a way that prevents breaches with incentives for results that go beyond the contracted requirements -- not in a way that outlines only post-breach punishments.
  • Think carefully before signing a long-term agreement   In general, service providers want to engage enterprises with longer-term contracts that last for five or more years. If CIOs agree to long-term contracts, they should be sure to craft strong termination clauses that enable them to cancel a contract after certain numbers or types of incidents. Also, CIOs should be aware that the longer the enterprise remains with a single vendor, the more dependent on that vendor it will become. While outsourcing frees organizations to focus on their core competencies, it also tends to decrease the company's ability to handle such functions on its own.
  • Reserve the right to renegotiate  As with any new partnership, problems become most apparent after the relationship gets underway. CIOs should ensure that they can renegotiate a contract after a certain period of time to adjust any elements that aren't working.
  • Audit your service providers   CIOs should ensure that contracts with service providers include "right to audit" clauses. Indicate how the relationship will be monitored and how results will be measured. Rasmussen says enterprises must be "very diligent in following through on your right-to-audit clauses to make sure that your contractors are doing what they say they're going to do."
  • Watch out for liability clauses   According to a March 21, 2006 Gartner report, outsourcers sometimes agree to limits of liability that add up to no more than one month's total revenue or $1 million, whichever is less. But the fine print typically reads that outsourcers will only agree to such liability if the customer can prove that the problem was entirely and solely the outsourcer's fault. That's a high burden of proof because most aspects of the relationship are cooperative between the client and the service provider, making it difficult to lay blame entirely on the service provider.

IT outsourcing can be helpful to organizations, but their first priority in structuring outsourcing agreements must be self-protection. By ensuring that outsourcers comply with laws and policies, enterprises can pave the way for a solid partnership that is beneficial for both parties. The best way for CIOs to ensure they're getting a good deal, Rasmussen says, is to do their homework up front and actively manage the relationship after it's in effect.

"It's up to the organization to clearly define in their contracts what they expect, and then to do due diligence to investigate the vendor's background for security," he says. "It's also up to the organization to make sure their vendor is meeting their security requirements."

Tara Swords is a Chicago-based journalist who has written about business and technology for nearly 10 years.

Featured Local Company

Advanced System Designs

3092637944
100 Yordy
Morton, IL

Related Articles
- The Realities of IT Outsourcing 101 Illinois
For more than a decade, public and private organizations have considered outsourcing some or all IT functions as a viable option. A recent Gartner report estimated that worldwide spending on IT outsourcing will rise from $191 billion in 2004 to $267 billion by 2009.
- Ensuring Email Security and Availability in Healthcare Illinois
- In-House Development Illinois
- Outsourcing Link Building Illinois
- SEO And Outsourcing Inbound Link Building Illinois
- McAfee Wireless Home Network Security Illinois
- Should IT Security Be Outsourced? Illinois
- Benchmarking the Outsourcers Illinois
- IT Security Information Illinois
- Making the Case for Managed Security Services Illinois
Regional Articles
- Ensuring Security in an Outsourcing Relationship Addison IL
- Ensuring Security in an Outsourcing Relationship Algonquin IL
- Ensuring Security in an Outsourcing Relationship Alsip IL
- Ensuring Security in an Outsourcing Relationship Alton IL
- Ensuring Security in an Outsourcing Relationship Arlington Heights IL
- Ensuring Security in an Outsourcing Relationship Aurora IL
- Ensuring Security in an Outsourcing Relationship Barrington IL
- Ensuring Security in an Outsourcing Relationship Bartlett IL
- Ensuring Security in an Outsourcing Relationship Batavia IL
- Ensuring Security in an Outsourcing Relationship Belleville IL
- Ensuring Security in an Outsourcing Relationship Bellwood IL
- Ensuring Security in an Outsourcing Relationship Belvidere IL
- Ensuring Security in an Outsourcing Relationship Bensenville IL
- Ensuring Security in an Outsourcing Relationship Berwyn IL
- Ensuring Security in an Outsourcing Relationship Bloomingdale IL
- Ensuring Security in an Outsourcing Relationship Bloomington IL
- Ensuring Security in an Outsourcing Relationship Blue Island IL
- Ensuring Security in an Outsourcing Relationship Bolingbrook IL
- Ensuring Security in an Outsourcing Relationship Bourbonnais IL
- Ensuring Security in an Outsourcing Relationship Bridgeview IL
- Ensuring Security in an Outsourcing Relationship Buffalo Grove IL
- Ensuring Security in an Outsourcing Relationship Calumet City IL
- Ensuring Security in an Outsourcing Relationship Carbondale IL
- Ensuring Security in an Outsourcing Relationship Carol Stream IL
- Ensuring Security in an Outsourcing Relationship Carpentersville IL
- Ensuring Security in an Outsourcing Relationship Champaign IL
- Ensuring Security in an Outsourcing Relationship Chicago Heights IL
- Ensuring Security in an Outsourcing Relationship Chicago IL
- Ensuring Security in an Outsourcing Relationship Cicero IL
- Ensuring Security in an Outsourcing Relationship Clarendon Hills IL
- Ensuring Security in an Outsourcing Relationship Collinsville IL
- Ensuring Security in an Outsourcing Relationship Country Club Hills IL
- Ensuring Security in an Outsourcing Relationship Crete IL
- Ensuring Security in an Outsourcing Relationship Crystal Lake IL
- Ensuring Security in an Outsourcing Relationship Danville IL
- Ensuring Security in an Outsourcing Relationship Decatur IL
- Ensuring Security in an Outsourcing Relationship Deerfield IL
- Ensuring Security in an Outsourcing Relationship Dekalb IL
- Ensuring Security in an Outsourcing Relationship Des Plaines IL
- Ensuring Security in an Outsourcing Relationship Dolton IL
- Ensuring Security in an Outsourcing Relationship Downers Grove IL
- Ensuring Security in an Outsourcing Relationship East Moline IL
- Ensuring Security in an Outsourcing Relationship East Peoria IL
- Ensuring Security in an Outsourcing Relationship East Saint Louis IL
- Ensuring Security in an Outsourcing Relationship Edwardsville IL
- Ensuring Security in an Outsourcing Relationship Effingham IL
- Ensuring Security in an Outsourcing Relationship Elgin IL
- Ensuring Security in an Outsourcing Relationship Elk Grove Village IL
- Ensuring Security in an Outsourcing Relationship Elmhurst IL
- Ensuring Security in an Outsourcing Relationship Elmwood Park IL
- Ensuring Security in an Outsourcing Relationship Evanston IL
- Ensuring Security in an Outsourcing Relationship Evergreen Park IL
- Ensuring Security in an Outsourcing Relationship Fairview Heights IL
- Ensuring Security in an Outsourcing Relationship Franklin Park IL
- Ensuring Security in an Outsourcing Relationship Freeport IL
- Ensuring Security in an Outsourcing Relationship Galesburg IL
- Ensuring Security in an Outsourcing Relationship Glen Ellyn IL
- Ensuring Security in an Outsourcing Relationship Glendale Heights IL
- Ensuring Security in an Outsourcing Relationship Glenview IL
- Ensuring Security in an Outsourcing Relationship Godfrey IL
- Ensuring Security in an Outsourcing Relationship Granite City IL
- Ensuring Security in an Outsourcing Relationship Grayslake IL
- Ensuring Security in an Outsourcing Relationship Gurnee IL
- Ensuring Security in an Outsourcing Relationship Harvey IL
- Ensuring Security in an Outsourcing Relationship Harwood Heights IL
- Ensuring Security in an Outsourcing Relationship Hazel Crest IL
- Ensuring Security in an Outsourcing Relationship Highland Park IL
- Ensuring Security in an Outsourcing Relationship Hinsdale IL
- Ensuring Security in an Outsourcing Relationship Homewood IL
- Ensuring Security in an Outsourcing Relationship Jacksonville IL
- Ensuring Security in an Outsourcing Relationship Joliet IL
- Ensuring Security in an Outsourcing Relationship Kankakee IL
- Ensuring Security in an Outsourcing Relationship Kewanee IL
- Ensuring Security in an Outsourcing Relationship La Grange IL
- Ensuring Security in an Outsourcing Relationship Lake Bluff IL
- Ensuring Security in an Outsourcing Relationship Lake Villa IL
- Ensuring Security in an Outsourcing Relationship Lake Zurich IL
- Ensuring Security in an Outsourcing Relationship Lansing IL
- Ensuring Security in an Outsourcing Relationship Lemont IL
- Ensuring Security in an Outsourcing Relationship Libertyville IL
- Ensuring Security in an Outsourcing Relationship Lisle IL
- Ensuring Security in an Outsourcing Relationship Lockport IL
- Ensuring Security in an Outsourcing Relationship Lombard IL
- Ensuring Security in an Outsourcing Relationship Loves Park IL
- Ensuring Security in an Outsourcing Relationship Machesney Park IL
- Ensuring Security in an Outsourcing Relationship Matteson IL
- Ensuring Security in an Outsourcing Relationship Mattoon IL
- Ensuring Security in an Outsourcing Relationship Maywood IL
- Ensuring Security in an Outsourcing Relationship Mchenry IL
- Ensuring Security in an Outsourcing Relationship Melrose Park IL
- Ensuring Security in an Outsourcing Relationship Midlothian IL
- Ensuring Security in an Outsourcing Relationship Mokena IL
- Ensuring Security in an Outsourcing Relationship Moline IL
- Ensuring Security in an Outsourcing Relationship Morris IL
- Ensuring Security in an Outsourcing Relationship Morton Grove IL
- Ensuring Security in an Outsourcing Relationship Morton IL
- Ensuring Security in an Outsourcing Relationship Mount Prospect IL
- Ensuring Security in an Outsourcing Relationship Mundelein IL
- Ensuring Security in an Outsourcing Relationship Murphysboro IL
- Ensuring Security in an Outsourcing Relationship Naperville IL
- Ensuring Security in an Outsourcing Relationship New Lenox IL
- Ensuring Security in an Outsourcing Relationship Niles IL
- Ensuring Security in an Outsourcing Relationship Normal IL
- Ensuring Security in an Outsourcing Relationship North Chicago IL
- Ensuring Security in an Outsourcing Relationship Northbrook IL
- Ensuring Security in an Outsourcing Relationship O Fallon IL
- Ensuring Security in an Outsourcing Relationship Oak Forest IL
- Ensuring Security in an Outsourcing Relationship Oak Lawn IL
- Ensuring Security in an Outsourcing Relationship Oak Park IL
- Ensuring Security in an Outsourcing Relationship Orland Park IL
- Ensuring Security in an Outsourcing Relationship Palatine IL
- Ensuring Security in an Outsourcing Relationship Palos Hills IL
- Ensuring Security in an Outsourcing Relationship Park Forest IL
- Ensuring Security in an Outsourcing Relationship Park Ridge IL
- Ensuring Security in an Outsourcing Relationship Pekin IL
- Ensuring Security in an Outsourcing Relationship Peoria IL
- Ensuring Security in an Outsourcing Relationship Plainfield IL
- Ensuring Security in an Outsourcing Relationship Prospect Heights IL
- Ensuring Security in an Outsourcing Relationship Quincy IL
- Ensuring Security in an Outsourcing Relationship Riverdale IL
- Ensuring Security in an Outsourcing Relationship Rochelle IL
- Ensuring Security in an Outsourcing Relationship Rock Falls IL
- Ensuring Security in an Outsourcing Relationship Rock Island IL
- Ensuring Security in an Outsourcing Relationship Rockford IL
- Ensuring Security in an Outsourcing Relationship Rolling Meadows IL
- Ensuring Security in an Outsourcing Relationship Romeoville IL
- Ensuring Security in an Outsourcing Relationship Roscoe IL
- Ensuring Security in an Outsourcing Relationship Roselle IL
- Ensuring Security in an Outsourcing Relationship Round Lake IL
- Ensuring Security in an Outsourcing Relationship Saint Charles IL
- Ensuring Security in an Outsourcing Relationship Schaumburg IL
- Ensuring Security in an Outsourcing Relationship Skokie IL
- Ensuring Security in an Outsourcing Relationship South Elgin IL
- Ensuring Security in an Outsourcing Relationship South Holland IL
- Ensuring Security in an Outsourcing Relationship Springfield IL
- Ensuring Security in an Outsourcing Relationship Streamwood IL
- Ensuring Security in an Outsourcing Relationship Streator IL
- Ensuring Security in an Outsourcing Relationship Sycamore IL
- Ensuring Security in an Outsourcing Relationship Taylorville IL
- Ensuring Security in an Outsourcing Relationship Tinley Park IL
- Ensuring Security in an Outsourcing Relationship Urbana IL
- Ensuring Security in an Outsourcing Relationship Vernon Hills IL
- Ensuring Security in an Outsourcing Relationship Villa Park IL
- Ensuring Security in an Outsourcing Relationship Waukegan IL
- Ensuring Security in an Outsourcing Relationship West Chicago IL
- Ensuring Security in an Outsourcing Relationship Westchester IL
- Ensuring Security in an Outsourcing Relationship Westmont IL
- Ensuring Security in an Outsourcing Relationship Wheaton IL
- Ensuring Security in an Outsourcing Relationship Wheeling IL
- Ensuring Security in an Outsourcing Relationship Wilmette IL
- Ensuring Security in an Outsourcing Relationship Wood Dale IL
- Ensuring Security in an Outsourcing Relationship Woodridge IL
- Ensuring Security in an Outsourcing Relationship Woodstock IL
- Ensuring Security in an Outsourcing Relationship Zion IL
Related Local Events
The CIO Agenda - 2010 and Beyond
Dates: 11/5/2009 - 11/5/2009
Location: The Donald E. Stephens Convention Center
Rosemont, IL
View Details

Information Systems Governance Strategies
Dates: 9/24/2009 - 9/24/2009
Location: The Donald E. Stephens Convention Center
Rosemont, IL
View Details

GO SECURE 2009
Dates: 9/17/2009 - 9/17/2009
Location: The Peoria Castle Lodge
Peoria, IL
View Details

WiMAX World Americas
Dates: 9/15/2009 - 9/17/2009
Location: McCormick Place
Chicago, IL
View Details

ANNUAL LEAN SIX SIGMA IN SERVICE & TRANSACTIONAL ENVIRONMENTS CONFERENCE
Dates: 8/18/2009 - 8/23/2009
Location: Chicago Hilton
Chicago, IL
View Details

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History