SHARE
Facebook X Pinterest WhatsApp

What Your CEO Needs to Know About the Cloud

Feb 21, 2012

“Cloud services” have arrived. Enterprises have either subscribed to cloud services or are seriously considering moving some of their IT infrastructure to the cloud. From an IT point of view, however, the cloud is not as new as it seems.

In fact, most CEOs already know quite a bit about the potential benefits and pitfalls of cloud services.  Consider an application service provider (ASP) transaction circa 2000. Even back then, cost, flexibility and the promise of eliminating at least some of a company’s IT infrastructure argued in favor of the ASP solution. Service level agreements (SLAs) were entering our lexicon. Information security was nascent. One of the overarching concerns was relinquishing control to the vendor, especially for mission-critical applications. That general concern, however, probably found its genesis in the mid-1980s, with the advent of outsourcing arrangements.

Fast forward to 2012, to the world of:

  • the public cloud (infrastructure furnished to general public);

  • the private cloud (infrastructure operated for specific customers);

  • the hybrid cloud (a combination of public and private clouds);

  • and the various cloud services models: software as a service (SaaS), platform as a service (PaaS) and infrastructure as a service (IaaS).

To be sure, the technologies (such as virtualization) have advanced, but in the end, a private cloud is still a remote data center, and SaaS is but an ASP under a different name. With a few exceptions, the conversation today between a CEO and CIO regarding a particular cloud service should not be terribly different from the conversation held in 2000 about an ASP solution. With cloud services, there is no reason to reinvent the wheel when it comes to helping your CEO understand the business implications of the solutions you’re recommending.

While a standard framework to assess each cloud service should be used, by definition each assessment should be different, as no two use cases, or prototypical data sets, will be the same. Email is not ERP, which is not CRM. Whether your company operates in a heavily regulated industry, such as financial services or health care, should weigh on the advisability of selecting a particular cloud service.

My suggested framework consists of three parts:

  1. understanding all facets of the current solution;

  2. conducting due diligence (technological, organizational and financial) about the proposed cloud service/provider; and

  3. ensuring risk mitigation by negotiating certain protective provisions and remedies into the services agreement, if possible, and taking certain preventive measures, regardless of whether such an agreement adequately addresses the underlying concerns.

Understanding every aspect of the current solution is obvious enough, but its importance cannot be overstated. Consider information security, which continues to be viewed as one of the biggest impediments to the adoption of cloud services. At a minimum, your assessment should show not only the security measures available to protect the company’s IT infrastructure, but also how well those measures have, in fact, been implemented. Put simply, know your baseline and current risk profile.

Due diligence requires slightly more explanation. While a request for proposal is generally not necessary, care should be taken to understand whether the cloud service is in fact a “composite service” (meaning that it leverages the services of other cloud vendors, thus amplifying risk) and to request the SLA (if one is not readily provided). Your company should understand the vendor’s approach to data privacy and information security — including the tools used, historical breaches and root causes, if available, and remediation — as well as the vendor’s willingness to assist your company in its efforts to comply with statutory or regulatory requirements.

In fact, it is this focus on data privacy, information security and compliance that will most distinguish between the process of assessing a particular cloud service in 2012 and  evaluating an ASP solution back in 2000.

When selecting a cloud service provider it’s important to consider the vendor’s financial stability, and its organizational experience in running a data center or providing a hosted (cloud) service. The results of this due diligence should inform your contract negotiations. For example, if a question exists about the financial viability of the cloud vendor and your company has  the technical capability to operate a system internally or through another trusted vendor, remedies such as a source code escrow should be considered.

Recommended for you...

7 Principles of Quality Management
Kara Sherrer
Sep 2, 2022
What is a Quality Management System (QMS)?
Kara Sherrer
Aug 25, 2022
What is Supply Chain Management?
Kara Sherrer
Aug 12, 2022
Asana vs Clickup: Compare Project Management Software
Jenna Phipps
Jun 23, 2022
CIO Insight Logo

CIO Insight offers thought leadership and best practices in the IT security and management industry while providing expert recommendations on software solutions for IT leaders. It is the trusted resource for security professionals who need to maintain regulatory compliance for their teams and organizations. CIO Insight is an ideal website for IT decision makers, systems integrators and administrators, and IT managers to stay informed about emerging technologies, software developments and trends in the IT security and management industry.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.