Ensuring Security in an Outsourcing Relationship Ohio

More organizations are outsourcing critical IT functions to third parties. At the same time, they are under strict mandates to maintain records, protect consumer privacy, and report data breaches -- mandates that significantly affect these outsourcing agreements.

Local Companies

NovaCoast Inc.
(513) 583-8625
600 West Loveland Avenue
Loveland, OH
Advanced Computer Graphics Inc.
(513) 936-5060
10895 Indeco Drive
Cincinnati, OH
NextStep Networking Inc.
(513) 792-3400
10865 Indeco Drive
Cincinnati, OH
Data Processing Sciences Corp.
(513) 791-7100
10810 Kenwood Road
Cincinnati, OH
Solutions Guided Technologies, Inc.
(513) 753-3323
33 East Main Street
Amelia, OH
SCS Technologies
(513) 563-6400
337 West Benson Street
Reading, OH
Zipscene
(513) 477-9090
2118 Saint James Avenue
Cincinnati, OH
Connective Computing Inc.
(513) 475-5660
2200 Victory Parkway
Cincinnati, OH
Apachi Networks
(513) 939-1111
4710 J Interstate Drive
Cincinnati, OH
D L P Technologies Inc.
(513) 232-7791
8080 Reading Road
Cincinnati, OH

 



By Tara Swords

More organizations are outsourcing critical IT functions to third parties. At the same time, they are under strict mandates to maintain records, protect consumer privacy, and report data breaches -- mandates that significantly affect these outsourcing agreements.

The benefits of outsourcing are understandable. If properly managed, outsourcers can help organizations focus on their own core competencies, cut costs, and get specialized help for a problem the enterprise can't solve with in-house resources. An April 2006 report from research firm Gartner, Inc., predicted that the outsourcing market will grow at a healthy rate of 7.3% from 2004 through 2009.

As enterprises outsource more data-related functions, they are simultaneously juggling a variety of regulations that govern what they can and can't do with their data. For example, California Senate Bill 1386, aimed at curtailing identity theft, requires any company that conducts business in California or has customers in the state to notify those customers if their electronic personal information is exposed through a security breach. The European Union (EU) Data Protection Directive has some very strict rules for the way companies collect, use, and process individuals' personal data in an EU country. Health care organizations must also comply with the Health Insurance Portability and Accountability Act (HIPAA), a complex piece of legislation that requires organizations to protect personal health information.

The problem with outsourcing data-related functions is that in the end, enterprises may still be held accountable for much of what the outsourcer does.

"You can't really transfer much of your liability," says Michael Rasmussen, vice president and analyst Forrester Research. "Nobody will accept liability A to Z in security."

To protect themselves in outsourcing arrangements, organizations need to specify exactly what the liabilities are for the outsourcer  in service-level agreements (SLAs). These agreements should include provisions to ensure that service providers are in compliance -- or limit the enterprise's liability in the event of noncompliance. Here are some strategies:

  • Ask for what you want  Negotiations almost never result in one party getting everything it wants. Before you begin, you need to know what points are non-negotiable and which are less critical. But don't start compromising before you sit down at the table. "Start the negotiation with what is the ideal situation for yourself. Then work with your business partner to define what's feasible," Rasmussen says.
  • Choose a jurisdiction  CIOs should understand that the service provider's home-country rules apply unless the contract names a different governing jurisdiction. For that reason, Rasmussen says, some organizations are building models that take different countries' laws into account. "Organizations will set up some type of framework, such as assigning level one through five depending on the intellectual property laws in a specific jurisdiction," he says. "That will govern what type of outsourcing relationships they'll allow in those jurisdictions."
  • Include an NDA Nondisclosure agreements, or NDAs, should require the service provider and its employees to agree that they will not disclose any sensitive information or intellectual property about your company to any other party. Detail exactly what kinds of information the NDA covers, and specify that the information cannot be communicated in any way: verbally, through email, over the phone, on paper, or in video, for example. Make the NDA both broad and specific.
  • Reserve the right to run background checks -- then do it  It sounds like a hassle, but a company should run background checks on all service provider employees who will have access to its information. According to a November 8, 2005, report from Gartner, Inc., "The United States Sentencing Commission Organizational Sentencing Guidelines require that personnel screening be done to make sure that access to information and processes is not given to individuals who have a history of criminal behavior." In other words, an enterprise may be at least partly liable if a service provider employee has a criminal record and discloses or misuses the enterprise's data.
  • Negotiate to prevent problems  It's almost impossible to put a dollar amount on brand or reputation damage. For example, if a service provider sells sensitive customer data to identity thieves posing as a legitimate business, the enterprise must work to rebuild trust with customers -- an immeasurable task. That's why it's important to structure contracts in a way that prevents breaches with incentives for results that go beyond the contracted requirements -- not in a way that outlines only post-breach punishments.
  • Think carefully before signing a long-term agreement   In general, service providers want to engage enterprises with longer-term contracts that last for five or more years. If CIOs agree to long-term contracts, they should be sure to craft strong termination clauses that enable them to cancel a contract after certain numbers or types of incidents. Also, CIOs should be aware that the longer the enterprise remains with a single vendor, the more dependent on that vendor it will become. While outsourcing frees organizations to focus on their core competencies, it also tends to decrease the company's ability to handle such functions on its own.
  • Reserve the right to renegotiate  As with any new partnership, problems become most apparent after the relationship gets underway. CIOs should ensure that they can renegotiate a contract after a certain period of time to adjust any elements that aren't working.
  • Audit your service providers   CIOs should ensure that contracts with service providers include "right to audit" clauses. Indicate how the relationship will be monitored and how results will be measured. Rasmussen says enterprises must be "very diligent in following through on your right-to-audit clauses to make sure that your contractors are doing what they say they're going to do."
  • Watch out for liability clauses   According to a March 21, 2006 Gartner report, outsourcers sometimes agree to limits of liability that add up to no more than one month's total revenue or $1 million, whichever is less. But the fine print typically reads that outsourcers will only agree to such liability if the customer can prove that the problem was entirely and solely the outsourcer's fault. That's a high burden of proof because most aspects of the relationship are cooperative between the client and the service provider, making it difficult to lay blame entirely on the service provider.

IT outsourcing can be helpful to organizations, but their first priority in structuring outsourcing agreements must be self-protection. By ensuring that outsourcers comply with laws and policies, enterprises can pave the way for a solid partnership that is beneficial for both parties. The best way for CIOs to ensure they're getting a good deal, Rasmussen says, is to do their homework up front and actively manage the relationship after it's in effect.

"It's up to the organization to clearly define in their contracts what they expect, and then to do due diligence to investigate the vendor's background for security," he says. "It's also up to the organization to make sure their vendor is meeting their security requirements."

Tara Swords is a Chicago-based journalist who has written about business and technology for nearly 10 years.

Featured Local Company

NovaCoast Inc.

(513) 583-8625
600 West Loveland Avenue
Loveland, OH

Related Articles
- Ensuring Email Security and Availability in Healthcare Ohio
As with many other industries, email has become a mission-critical component for every individual and group in a healthcare organization, from those providing patient care to those who oversee the daily management of business operations. In the patient/physician setting, email is transforming communication, treatment, and care, while on the operations side, millions of transactions are processed each day via email at a fraction of the time and costs associated with hard copies. However, if left unprotected, or unavailable, email can interfere with a healthcare organization's primary mission of providing high-quality patient care.
- IT Security Information Ohio
- The Realities of IT Outsourcing 101 Ohio
- Outsourcing Link Building Ohio
- Benchmarking the Outsourcers Ohio
- Should IT Security Be Outsourced? Ohio
- Making the Case for Managed Security Services Ohio
- In-House Development Ohio
- McAfee Wireless Home Network Security Ohio
- SEO And Outsourcing Inbound Link Building Ohio
Regional Articles
- Ensuring Security in an Outsourcing Relationship Akron OH
- Ensuring Security in an Outsourcing Relationship Alliance OH
- Ensuring Security in an Outsourcing Relationship Amelia OH
- Ensuring Security in an Outsourcing Relationship Ashland OH
- Ensuring Security in an Outsourcing Relationship Ashtabula OH
- Ensuring Security in an Outsourcing Relationship Athens OH
- Ensuring Security in an Outsourcing Relationship Avon Lake OH
- Ensuring Security in an Outsourcing Relationship Barberton OH
- Ensuring Security in an Outsourcing Relationship Batavia OH
- Ensuring Security in an Outsourcing Relationship Bay Village OH
- Ensuring Security in an Outsourcing Relationship Beachwood OH
- Ensuring Security in an Outsourcing Relationship Bedford OH
- Ensuring Security in an Outsourcing Relationship Bellefontaine OH
- Ensuring Security in an Outsourcing Relationship Bowling Green OH
- Ensuring Security in an Outsourcing Relationship Broadview Heights OH
- Ensuring Security in an Outsourcing Relationship Brook Park OH
- Ensuring Security in an Outsourcing Relationship Brunswick OH
- Ensuring Security in an Outsourcing Relationship Bucyrus OH
- Ensuring Security in an Outsourcing Relationship Canal Winchester OH
- Ensuring Security in an Outsourcing Relationship Canfield OH
- Ensuring Security in an Outsourcing Relationship Canton OH
- Ensuring Security in an Outsourcing Relationship Celina OH
- Ensuring Security in an Outsourcing Relationship Chagrin Falls OH
- Ensuring Security in an Outsourcing Relationship Chardon OH
- Ensuring Security in an Outsourcing Relationship Chillicothe OH
- Ensuring Security in an Outsourcing Relationship Cincinnati OH
- Ensuring Security in an Outsourcing Relationship Circleville OH
- Ensuring Security in an Outsourcing Relationship Cleveland OH
- Ensuring Security in an Outsourcing Relationship Columbus OH
- Ensuring Security in an Outsourcing Relationship Conneaut OH
- Ensuring Security in an Outsourcing Relationship Coshocton OH
- Ensuring Security in an Outsourcing Relationship Cuyahoga Falls OH
- Ensuring Security in an Outsourcing Relationship Dayton OH
- Ensuring Security in an Outsourcing Relationship Defiance OH
- Ensuring Security in an Outsourcing Relationship Delaware OH
- Ensuring Security in an Outsourcing Relationship Dublin OH
- Ensuring Security in an Outsourcing Relationship East Liverpool OH
- Ensuring Security in an Outsourcing Relationship Eastlake OH
- Ensuring Security in an Outsourcing Relationship Eaton OH
- Ensuring Security in an Outsourcing Relationship Elyria OH
- Ensuring Security in an Outsourcing Relationship Euclid OH
- Ensuring Security in an Outsourcing Relationship Fairborn OH
- Ensuring Security in an Outsourcing Relationship Fairfield OH
- Ensuring Security in an Outsourcing Relationship Findlay OH
- Ensuring Security in an Outsourcing Relationship Fostoria OH
- Ensuring Security in an Outsourcing Relationship Franklin OH
- Ensuring Security in an Outsourcing Relationship Fremont OH
- Ensuring Security in an Outsourcing Relationship Galion OH
- Ensuring Security in an Outsourcing Relationship Gallipolis OH
- Ensuring Security in an Outsourcing Relationship Galloway OH
- Ensuring Security in an Outsourcing Relationship Girard OH
- Ensuring Security in an Outsourcing Relationship Grove City OH
- Ensuring Security in an Outsourcing Relationship Hamilton OH
- Ensuring Security in an Outsourcing Relationship Heath OH
- Ensuring Security in an Outsourcing Relationship Hilliard OH
- Ensuring Security in an Outsourcing Relationship Hubbard OH
- Ensuring Security in an Outsourcing Relationship Ironton OH
- Ensuring Security in an Outsourcing Relationship Kent OH
- Ensuring Security in an Outsourcing Relationship Lakewood OH
- Ensuring Security in an Outsourcing Relationship Lancaster OH
- Ensuring Security in an Outsourcing Relationship Lebanon OH
- Ensuring Security in an Outsourcing Relationship Lima OH
- Ensuring Security in an Outsourcing Relationship Lorain OH
- Ensuring Security in an Outsourcing Relationship Loveland OH
- Ensuring Security in an Outsourcing Relationship Madison OH
- Ensuring Security in an Outsourcing Relationship Maineville OH
- Ensuring Security in an Outsourcing Relationship Mansfield OH
- Ensuring Security in an Outsourcing Relationship Maple Heights OH
- Ensuring Security in an Outsourcing Relationship Marion OH
- Ensuring Security in an Outsourcing Relationship Marysville OH
- Ensuring Security in an Outsourcing Relationship Mason OH
- Ensuring Security in an Outsourcing Relationship Massillon OH
- Ensuring Security in an Outsourcing Relationship Maumee OH
- Ensuring Security in an Outsourcing Relationship Medina OH
- Ensuring Security in an Outsourcing Relationship Mentor OH
- Ensuring Security in an Outsourcing Relationship Miamisburg OH
- Ensuring Security in an Outsourcing Relationship Middletown OH
- Ensuring Security in an Outsourcing Relationship Milford OH
- Ensuring Security in an Outsourcing Relationship Millersburg OH
- Ensuring Security in an Outsourcing Relationship Mount Vernon OH
- Ensuring Security in an Outsourcing Relationship Napoleon OH
- Ensuring Security in an Outsourcing Relationship New Carlisle OH
- Ensuring Security in an Outsourcing Relationship New Philadelphia OH
- Ensuring Security in an Outsourcing Relationship Newark OH
- Ensuring Security in an Outsourcing Relationship North Olmsted OH
- Ensuring Security in an Outsourcing Relationship North Ridgeville OH
- Ensuring Security in an Outsourcing Relationship North Royalton OH
- Ensuring Security in an Outsourcing Relationship Olmsted Falls OH
- Ensuring Security in an Outsourcing Relationship Oregon OH
- Ensuring Security in an Outsourcing Relationship Oxford OH
- Ensuring Security in an Outsourcing Relationship Painesville OH
- Ensuring Security in an Outsourcing Relationship Pataskala OH
- Ensuring Security in an Outsourcing Relationship Perrysburg OH
- Ensuring Security in an Outsourcing Relationship Pickerington OH
- Ensuring Security in an Outsourcing Relationship Piqua OH
- Ensuring Security in an Outsourcing Relationship Portsmouth OH
- Ensuring Security in an Outsourcing Relationship Ravenna OH
- Ensuring Security in an Outsourcing Relationship Reynoldsburg OH
- Ensuring Security in an Outsourcing Relationship Rocky River OH
- Ensuring Security in an Outsourcing Relationship Salem OH
- Ensuring Security in an Outsourcing Relationship Sandusky OH
- Ensuring Security in an Outsourcing Relationship Sidney OH
- Ensuring Security in an Outsourcing Relationship Solon OH
- Ensuring Security in an Outsourcing Relationship Springboro OH
- Ensuring Security in an Outsourcing Relationship Springfield OH
- Ensuring Security in an Outsourcing Relationship Steubenville OH
- Ensuring Security in an Outsourcing Relationship Stow OH
- Ensuring Security in an Outsourcing Relationship Strongsville OH
- Ensuring Security in an Outsourcing Relationship Sylvania OH
- Ensuring Security in an Outsourcing Relationship Tallmadge OH
- Ensuring Security in an Outsourcing Relationship Tiffin OH
- Ensuring Security in an Outsourcing Relationship Tipp City OH
- Ensuring Security in an Outsourcing Relationship Toledo OH
- Ensuring Security in an Outsourcing Relationship Troy OH
- Ensuring Security in an Outsourcing Relationship Twinsburg OH
- Ensuring Security in an Outsourcing Relationship Van Wert OH
- Ensuring Security in an Outsourcing Relationship Vandalia OH
- Ensuring Security in an Outsourcing Relationship Vermilion OH
- Ensuring Security in an Outsourcing Relationship Wadsworth OH
- Ensuring Security in an Outsourcing Relationship Wapakoneta OH
- Ensuring Security in an Outsourcing Relationship Warren OH
- Ensuring Security in an Outsourcing Relationship Washington Court House OH
- Ensuring Security in an Outsourcing Relationship West Chester OH
- Ensuring Security in an Outsourcing Relationship Westerville OH
- Ensuring Security in an Outsourcing Relationship Westlake OH
- Ensuring Security in an Outsourcing Relationship Wickliffe OH
- Ensuring Security in an Outsourcing Relationship Willoughby OH
- Ensuring Security in an Outsourcing Relationship Wooster OH
- Ensuring Security in an Outsourcing Relationship Xenia OH
- Ensuring Security in an Outsourcing Relationship Youngstown OH
- Ensuring Security in an Outsourcing Relationship Zanesville OH
Related Articles
- Benchmarking the Outsourcers Ohio
If managed correctly, outsourcing can provide value and improve productivity. This trend was made evident in a recent Gartner Group report, Gartner on Outsourcing, Q404. In it, the researcher found that the primary motivation for outsourced development has been shifting from cost-only to cost-and-quality, as well as to cost-and-business impact. As outsourcing clients grow more concerned with quality, expertise, and cultural compatibility, Gartner expects that the extreme focus on cost savings will moderate. The report concludes that the market for outsourced application development will grow from $34.9 billion in 2003 to $47.5 billion by 2008.
- In-House Development Ohio
- Ensuring Email Security and Availability in Healthcare Ohio
- Making the Case for Managed Security Services Ohio
- The Realities of IT Outsourcing 101 Ohio
- Should IT Security Be Outsourced? Ohio
- Outsourcing Link Building Ohio
- IT Security Information Ohio
- McAfee Wireless Home Network Security Ohio
- SEO And Outsourcing Inbound Link Building Ohio

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History