UIMCert asks IT Security questions, which have to be answered in the context of Cloud Computing
According to experts and suppliers Cloud Computing is a future oriented form of information processing/computing. Renowned suppliers have developed concepts, which are suitable for it, to open the market. Since the offer is relevant also to small and medium-sized companies in clear scope, is for these - and not only for these - the problem of the selection of the right supplier a point of discussion.
At first place, to opinion of the UIMCert the question must be answered which form of Cloud Computing is appropriate for the problem to be solved. The UIMCert has developed a questionnaire mainly based on the standard ISO/IEC 27001-02, which is made available for prospects on the home page of the UIMCert. It contains the following categories of questions in accordance with the certification standard:
- Management of the IT-security
- Quality of the risk management
- Existence of Business Continuity Concepts
- Quality of the technical solutions
- Existence of clear contractual solutions in form of SLAs
- Clear concepts of the archiving, distributed storing and deletion
- Qualitatively high class data protection concept
- Documented solutions with reference to the observance of relevant legislation
- Availability of qualified employees, as well as
- certificates on the sectors IT management, IT security, data protection.
The questionnaire of the UIMCert doesn't want to claim for completeness but rather should lead to a more intensive reflection over the concrete problems in company specific variations and should give a basis for deepening.
UIMCert points out that the presentation of certificates, especially of documents, which prove that the requests of the "State of the Art” are realized; respectively norms by national or international working groups are recognized in the relevant area, can be regarded as a quality criterion.
More information to the afore mentioned question categories, to the certification in accordance with ISO/IEC 27001, compliance in accordance with data protection legislation or to quality seals in the named areas and with reference to other audit standards under www.UIMCert.de