Ensuring Security in an Outsourcing Relationship Michigan

More organizations are outsourcing critical IT functions to third parties. At the same time, they are under strict mandates to maintain records, protect consumer privacy, and report data breaches -- mandates that significantly affect these outsourcing agreements.

Local Companies

oakood hospital
313 337 0450
1r462 linden st
dearborn, MI
Aspiryon
866-353-8184
24275 NW HWY
Southfield, MI
Busse H M & Associates
(616) 954-9933
6631 Waybridge Dr SE
Grand Rapids, MI
Wild Card
(269) 543-4014
2178 Lakeshore Dr
Fennville, MI
Lead Institute the
(734) 995-5222
6055 Jackson Rd
Ann Arbor, MI
Talon Group the
(616) 406-0984
4175 Parkway Pl SW Ste 104
Grandville, MI
Michigan Municipal League
(734) 662-3246
1675 Green Rd
Ann Arbor, MI
Quality Management Services
(734) 997-9629
2381 W Stadium Blvd
Ann Arbor, MI
Pearl Management
(313) 843-4107
9003 W Vernor Hwy
Detroit, MI
Keystone Property Mgt
(269) 685-8290
1183 Paula St
Plainwell, MI



By Tara Swords

More organizations are outsourcing critical IT functions to third parties. At the same time, they are under strict mandates to maintain records, protect consumer privacy, and report data breaches -- mandates that significantly affect these outsourcing agreements.

The benefits of outsourcing are understandable. If properly managed, outsourcers can help organizations focus on their own core competencies, cut costs, and get specialized help for a problem the enterprise can't solve with in-house resources. An April 2006 report from research firm Gartner, Inc., predicted that the outsourcing market will grow at a healthy rate of 7.3% from 2004 through 2009.

As enterprises outsource more data-related functions, they are simultaneously juggling a variety of regulations that govern what they can and can't do with their data. For example, California Senate Bill 1386, aimed at curtailing identity theft, requires any company that conducts business in California or has customers in the state to notify those customers if their electronic personal information is exposed through a security breach. The European Union (EU) Data Protection Directive has some very strict rules for the way companies collect, use, and process individuals' personal data in an EU country. Health care organizations must also comply with the Health Insurance Portability and Accountability Act (HIPAA), a complex piece of legislation that requires organizations to protect personal health information.

The problem with outsourcing data-related functions is that in the end, enterprises may still be held accountable for much of what the outsourcer does.

"You can't really transfer much of your liability," says Michael Rasmussen, vice president and analyst Forrester Research. "Nobody will accept liability A to Z in security."

To protect themselves in outsourcing arrangements, organizations need to specify exactly what the liabilities are for the outsourcer  in service-level agreements (SLAs). These agreements should include provisions to ensure that service providers are in compliance -- or limit the enterprise's liability in the event of noncompliance. Here are some strategies:

  • Ask for what you want  Negotiations almost never result in one party getting everything it wants. Before you begin, you need to know what points are non-negotiable and which are less critical. But don't start compromising before you sit down at the table. "Start the negotiation with what is the ideal situation for yourself. Then work with your business partner to define what's feasible," Rasmussen says.
  • Choose a jurisdiction  CIOs should understand that the service provider's home-country rules apply unless the contract names a different governing jurisdiction. For that reason, Rasmussen says, some organizations are building models that take different countries' laws into account. "Organizations will set up some type of framework, such as assigning level one through five depending on the intellectual property laws in a specific jurisdiction," he says. "That will govern what type of outsourcing relationships they'll allow in those jurisdictions."
  • Include an NDA Nondisclosure agreements, or NDAs, should require the service provider and its employees to agree that they will not disclose any sensitive information or intellectual property about your company to any other party. Detail exactly what kinds of information the NDA covers, and specify that the information cannot be communicated in any way: verbally, through email, over the phone, on paper, or in video, for example. Make the NDA both broad and specific.
  • Reserve the right to run background checks -- then do it  It sounds like a hassle, but a company should run background checks on all service provider employees who will have access to its information. According to a November 8, 2005, report from Gartner, Inc., "The United States Sentencing Commission Organizational Sentencing Guidelines require that personnel screening be done to make sure that access to information and processes is not given to individuals who have a history of criminal behavior." In other words, an enterprise may be at least partly liable if a service provider employee has a criminal record and discloses or misuses the enterprise's data.
  • Negotiate to prevent problems  It's almost impossible to put a dollar amount on brand or reputation damage. For example, if a service provider sells sensitive customer data to identity thieves posing as a legitimate business, the enterprise must work to rebuild trust with customers -- an immeasurable task. That's why it's important to structure contracts in a way that prevents breaches with incentives for results that go beyond the contracted requirements -- not in a way that outlines only post-breach punishments.
  • Think carefully before signing a long-term agreement   In general, service providers want to engage enterprises with longer-term contracts that last for five or more years. If CIOs agree to long-term contracts, they should be sure to craft strong termination clauses that enable them to cancel a contract after certain numbers or types of incidents. Also, CIOs should be aware that the longer the enterprise remains with a single vendor, the more dependent on that vendor it will become. While outsourcing frees organizations to focus on their core competencies, it also tends to decrease the company's ability to handle such functions on its own.
  • Reserve the right to renegotiate  As with any new partnership, problems become most apparent after the relationship gets underway. CIOs should ensure that they can renegotiate a contract after a certain period of time to adjust any elements that aren't working.
  • Audit your service providers   CIOs should ensure that contracts with service providers include "right to audit" clauses. Indicate how the relationship will be monitored and how results will be measured. Rasmussen says enterprises must be "very diligent in following through on your right-to-audit clauses to make sure that your contractors are doing what they say they're going to do."
  • Watch out for liability clauses   According to a March 21, 2006 Gartner report, outsourcers sometimes agree to limits of liability that add up to no more than one month's total revenue or $1 million, whichever is less. But the fine print typically reads that outsourcers will only agree to such liability if the customer can prove that the problem was entirely and solely the outsourcer's fault. That's a high burden of proof because most aspects of the relationship are cooperative between the client and the service provider, making it difficult to lay blame entirely on the service provider.

IT outsourcing can be helpful to organizations, but their first priority in structuring outsourcing agreements must be self-protection. By ensuring that outsourcers comply with laws and policies, enterprises can pave the way for a solid partnership that is beneficial for both parties. The best way for CIOs to ensure they're getting a good deal, Rasmussen says, is to do their homework up front and actively manage the relationship after it's in effect.

"It's up to the organization to clearly define in their contracts what they expect, and then to do due diligence to investigate the vendor's background for security," he says. "It's also up to the organization to make sure their vendor is meeting their security requirements."

Tara Swords is a Chicago-based journalist who has written about business and technology for nearly 10 years.

Featured Local Company

oakood hospital

313 337 0450
1r462 linden st
dearborn, MI

Regional Articles
- Ensuring Security in an Outsourcing Relationship Adrian MI
- Ensuring Security in an Outsourcing Relationship Allegan MI
- Ensuring Security in an Outsourcing Relationship Allen Park MI
- Ensuring Security in an Outsourcing Relationship Alpena MI
- Ensuring Security in an Outsourcing Relationship Ann Arbor MI
- Ensuring Security in an Outsourcing Relationship Auburn Hills MI
- Ensuring Security in an Outsourcing Relationship Battle Creek MI
- Ensuring Security in an Outsourcing Relationship Bay City MI
- Ensuring Security in an Outsourcing Relationship Belleville MI
- Ensuring Security in an Outsourcing Relationship Benton Harbor MI
- Ensuring Security in an Outsourcing Relationship Berkley MI
- Ensuring Security in an Outsourcing Relationship Big Rapids MI
- Ensuring Security in an Outsourcing Relationship Bloomfield Hills MI
- Ensuring Security in an Outsourcing Relationship Brighton MI
- Ensuring Security in an Outsourcing Relationship Burton MI
- Ensuring Security in an Outsourcing Relationship Cadillac MI
- Ensuring Security in an Outsourcing Relationship Canton MI
- Ensuring Security in an Outsourcing Relationship Cheboygan MI
- Ensuring Security in an Outsourcing Relationship Clarkston MI
- Ensuring Security in an Outsourcing Relationship Clinton Township MI
- Ensuring Security in an Outsourcing Relationship Clio MI
- Ensuring Security in an Outsourcing Relationship Coldwater MI
- Ensuring Security in an Outsourcing Relationship Commerce Township MI
- Ensuring Security in an Outsourcing Relationship Comstock Park MI
- Ensuring Security in an Outsourcing Relationship Davison MI
- Ensuring Security in an Outsourcing Relationship Dearborn Heights MI
- Ensuring Security in an Outsourcing Relationship Dearborn MI
- Ensuring Security in an Outsourcing Relationship Detroit MI
- Ensuring Security in an Outsourcing Relationship Dowagiac MI
- Ensuring Security in an Outsourcing Relationship East Lansing MI
- Ensuring Security in an Outsourcing Relationship Eastpointe MI
- Ensuring Security in an Outsourcing Relationship Eaton Rapids MI
- Ensuring Security in an Outsourcing Relationship Escanaba MI
- Ensuring Security in an Outsourcing Relationship Farmington MI
- Ensuring Security in an Outsourcing Relationship Fenton MI
- Ensuring Security in an Outsourcing Relationship Ferndale MI
- Ensuring Security in an Outsourcing Relationship Flat Rock MI
- Ensuring Security in an Outsourcing Relationship Flint MI
- Ensuring Security in an Outsourcing Relationship Flushing MI
- Ensuring Security in an Outsourcing Relationship Fort Gratiot MI
- Ensuring Security in an Outsourcing Relationship Fraser MI
- Ensuring Security in an Outsourcing Relationship Garden City MI
- Ensuring Security in an Outsourcing Relationship Gaylord MI
- Ensuring Security in an Outsourcing Relationship Gladwin MI
- Ensuring Security in an Outsourcing Relationship Grand Blanc MI
- Ensuring Security in an Outsourcing Relationship Grand Haven MI
- Ensuring Security in an Outsourcing Relationship Grand Ledge MI
- Ensuring Security in an Outsourcing Relationship Grand Rapids MI
- Ensuring Security in an Outsourcing Relationship Grandville MI
- Ensuring Security in an Outsourcing Relationship Grosse Pointe MI
- Ensuring Security in an Outsourcing Relationship Hamtramck MI
- Ensuring Security in an Outsourcing Relationship Harper Woods MI
- Ensuring Security in an Outsourcing Relationship Harrison Township MI
- Ensuring Security in an Outsourcing Relationship Hazel Park MI
- Ensuring Security in an Outsourcing Relationship Highland Park MI
- Ensuring Security in an Outsourcing Relationship Hillsdale MI
- Ensuring Security in an Outsourcing Relationship Holland MI
- Ensuring Security in an Outsourcing Relationship Holly MI
- Ensuring Security in an Outsourcing Relationship Holt MI
- Ensuring Security in an Outsourcing Relationship Howell MI
- Ensuring Security in an Outsourcing Relationship Hudsonville MI
- Ensuring Security in an Outsourcing Relationship Inkster MI
- Ensuring Security in an Outsourcing Relationship Ionia MI
- Ensuring Security in an Outsourcing Relationship Jackson MI
- Ensuring Security in an Outsourcing Relationship Jenison MI
- Ensuring Security in an Outsourcing Relationship Kalamazoo MI
- Ensuring Security in an Outsourcing Relationship Lake Orion MI
- Ensuring Security in an Outsourcing Relationship Lansing MI
- Ensuring Security in an Outsourcing Relationship Lapeer MI
- Ensuring Security in an Outsourcing Relationship Lincoln Park MI
- Ensuring Security in an Outsourcing Relationship Livonia MI
- Ensuring Security in an Outsourcing Relationship Ludington MI
- Ensuring Security in an Outsourcing Relationship Macomb MI
- Ensuring Security in an Outsourcing Relationship Marquette MI
- Ensuring Security in an Outsourcing Relationship Midland MI
- Ensuring Security in an Outsourcing Relationship Monroe MI
- Ensuring Security in an Outsourcing Relationship Mount Clemens MI
- Ensuring Security in an Outsourcing Relationship Mount Morris MI
- Ensuring Security in an Outsourcing Relationship Mount Pleasant MI
- Ensuring Security in an Outsourcing Relationship Muskegon MI
- Ensuring Security in an Outsourcing Relationship New Baltimore MI
- Ensuring Security in an Outsourcing Relationship Niles MI
- Ensuring Security in an Outsourcing Relationship Northville MI
- Ensuring Security in an Outsourcing Relationship Novi MI
- Ensuring Security in an Outsourcing Relationship Oak Park MI
- Ensuring Security in an Outsourcing Relationship Okemos MI
- Ensuring Security in an Outsourcing Relationship Owosso MI
- Ensuring Security in an Outsourcing Relationship Petoskey MI
- Ensuring Security in an Outsourcing Relationship Pinckney MI
- Ensuring Security in an Outsourcing Relationship Plymouth MI
- Ensuring Security in an Outsourcing Relationship Pontiac MI
- Ensuring Security in an Outsourcing Relationship Port Huron MI
- Ensuring Security in an Outsourcing Relationship Portage MI
- Ensuring Security in an Outsourcing Relationship Redford MI
- Ensuring Security in an Outsourcing Relationship Rochester MI
- Ensuring Security in an Outsourcing Relationship Rockford MI
- Ensuring Security in an Outsourcing Relationship Romulus MI
- Ensuring Security in an Outsourcing Relationship Roseville MI
- Ensuring Security in an Outsourcing Relationship Royal Oak MI
- Ensuring Security in an Outsourcing Relationship Saginaw MI
- Ensuring Security in an Outsourcing Relationship Saint Clair Shores MI
- Ensuring Security in an Outsourcing Relationship Saint Johns MI
- Ensuring Security in an Outsourcing Relationship Saline MI
- Ensuring Security in an Outsourcing Relationship Sault Sainte Marie MI
- Ensuring Security in an Outsourcing Relationship South Haven MI
- Ensuring Security in an Outsourcing Relationship South Lyon MI
- Ensuring Security in an Outsourcing Relationship Southfield MI
- Ensuring Security in an Outsourcing Relationship Southgate MI
- Ensuring Security in an Outsourcing Relationship Sterling Heights MI
- Ensuring Security in an Outsourcing Relationship Sturgis MI
- Ensuring Security in an Outsourcing Relationship Swartz Creek MI
- Ensuring Security in an Outsourcing Relationship Taylor MI
- Ensuring Security in an Outsourcing Relationship Temperance MI
- Ensuring Security in an Outsourcing Relationship Three Rivers MI
- Ensuring Security in an Outsourcing Relationship Traverse City MI
- Ensuring Security in an Outsourcing Relationship Trenton MI
- Ensuring Security in an Outsourcing Relationship Troy MI
- Ensuring Security in an Outsourcing Relationship Utica MI
- Ensuring Security in an Outsourcing Relationship Walled Lake MI
- Ensuring Security in an Outsourcing Relationship Warren MI
- Ensuring Security in an Outsourcing Relationship Waterford MI
- Ensuring Security in an Outsourcing Relationship West Bloomfield MI
- Ensuring Security in an Outsourcing Relationship Westland MI
- Ensuring Security in an Outsourcing Relationship White Lake MI
- Ensuring Security in an Outsourcing Relationship Wixom MI
- Ensuring Security in an Outsourcing Relationship Wyandotte MI
- Ensuring Security in an Outsourcing Relationship Wyoming MI
- Ensuring Security in an Outsourcing Relationship Ypsilanti MI
- Ensuring Security in an Outsourcing Relationship Zeeland MI
Related Articles
- Should IT Security Be Outsourced? Michigan
For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.
- SEO And Outsourcing Inbound Link Building Michigan
- Outsourcing Link Building Michigan
- Ensuring Email Security and Availability in Healthcare Michigan
- In-House Development Michigan
- McAfee Wireless Home Network Security Michigan
- IT Security Information Michigan
- The Realities of IT Outsourcing 101 Michigan
- Making the Case for Managed Security Services Michigan
- Benchmarking the Outsourcers Michigan

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History