Utility Computing - CIOInsight
Home arrow Utility Computing arrow The Legal Risks of SaaS
  Utility Computing


The Legal Risks of SaaS
By Christopher C. Cain and Kenny W. Hoeschen


Rate This Article:
Add This Article To:
Weigh the legal pros and cons of SaaS before rushing into a project that might not benefit your organization.

Even in this economic downturn, software-as-a-service continues to grow. IDC recently raised its 2009 projected growth rate for SaaS from 36 percent to 40.5 percent.

SaaS advantages over traditional software licensing, such as simpler transitions and low to no up-front costs, are well known. However, SaaS also introduces distinct risks related to software availability, data availability, data recovery and data security. Prudent CIOs must weigh the pros and cons of a SaaS offering before rushing into a deployment that may not be appropriate for their organization.

SaaS can provide significant advantages to an organization, particularly in a down economy when IT budgets are tight:

- First, a SaaS often allows a business to transfer primary control of the software from IT to the business unit. This can free up your IT department, giving it more time to spend on other initiatives;

- Second, SaaS typically requires little (if any) customization or configuration of the underlying software. That means the transition to a SaaS offering can be done quickly and without the need for drawn out and costly implementations and testing;

Resource Library:

- Third, SaaS often provides on-demand scalability, allowing the business to adjust its processing power and storage to match the peaks and lulls in its load levels.

- Fourth, a SaaS offering typically requires low-to-no costs up front -- no large license fee, no time and no materials. Instead, the business pays a monthly or annual fee for the service.

SaaS also raises many risks for a CIO to evaluate. Because the SaaS vendor will be hosting your business data in its environment, a CIO must consider and examine the considerable risks related to a potential data loss or data breach.

The SaaS vendor's capabilities (and warranties) must be carefully evaluated in each of these areas:

- Disaster recovery and business continuity;
- Protection against physical and electronic security vulnerabilities; 
- Data backups and ability to restore data in the event data is lost or corrupted.

CIOs must require their SaaS vendors to regularly report the results of an annual independent security audit (one type of which is a SAS 70 II audit).

Finally, some types of data, such as personally identifiable information (i.e., name, social security numbers, home addresses, birth dates), medical information, or credit card or other financial data may simply not be appropriate to be included in a SaaS delivery model.

So, before you sign off on that next request to purchase a SaaS offering, make sure as the CIO you take the time to do the appropriate investigation on the business solution to be served, the data involved and the costs-all as compared to a traditional software offering.

Many times, the SaaS choice may be the right one, but not always. Make sure you know the difference.

Christopher C. Cain is a partner and Kenny W. Hoeschen is an associate in the Information Technology & Outsourcing practice of law firm Foley & Lardner LLP.





Discuss The Legal Risks of SaaS
 
Wonderful article, guys. You make some solid points here. You covered the most...
>>> Post your comment now!
 

 
 
>>> More Utility Computing Articles          >>> More By Christopher C. Cain and Kenny W. Hoeschen
 


 
 
FEATURED SPONSORED CONTENT

    VMware  Business Infrastructure Virtualization: 

    The Source for Virtualization, IT Efficiency and IT Agility.


    Learn how VMware is the source for the world’s most trusted, flexible and dynamic virtualization solutions, from the datacenter to the desktop to the cloud.

          Go To The Source

    Brought to You By

FEATURED SPONSORED MESSAGE

    Build A More Efficient Data Center

    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have.


    Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives.

CIO STRATEGY
Tips for Implementing Your IT Strategy

Columbia University's Art Langer provides a playbook for executing your strategic IT plan.  

Sir Terrence Mathews and How to Grow Startups

RECENT NEWS

BIZTECH 3.0
By Brian P. Watson
What the M&A Wave Means for CIOs

Many analysts are predicting an uptick in M&A activity. CIOs: Are you ready to drop everything to handle te challenge?
KNOW IT ALL
By Ed Cone
Pulte CIO's Cloud Computing Horror Story

Tony Kontzer's post on the cloud gone wrong is drawing sharp comments from readers.

BOTTOM LINE
By Baseline Editors
How Can You Manage IT Projects Better?

IT project managers have their hands full today. What can they do make their work easier?
EDITORS' PICKS
 
 
LATEST STORIES

FEEDBACK

Ziff Davis Enterprise RSS Feeds
IT WHITE PAPERS
Technical WHITE PAPERS essential in the decision-making process for technology buyers!

See All White Papers

Sponsored Links
  • Reduce the cost of managing your mobile workers.
  • No Payments for Up to 6 Months on Orders over $500.
  • VMware. Business Infrastructure Virtualization.
  • up.time Easily Monitors Virtual/Physical/Cloud. Free Trial.
  • Find out 7 Ways to Drive Data Center Efficiency
  • Save up to 40% on calling costs with Avaya Aura™
  • Reduce risk, gain agility. See Progress Software.
  • ESET NOD32 Business Edition - Get your free trial now!
  • 10 Reasons to Upgrade to Windows Server 2008 R2.

  • eWEEK Quick LInks