User:Shawndouglas/sandbox/sublevel1

From LIMSWiki
Jump to navigationJump to search

Here we provide a concise listing of 18 questions your organization should be asking any cloud providers being considered for your cloud project. (A broader list of questions is discussed in the next subsection about RFIs.) As part of the discovery phase of your formal cloud project, some of these questions may have been asked prior, but many of them will likely not have been addressed in prior discussions. Most of these questions have already been addressed in prior sections of this guide, but a "shopping list" is always handy, yes? Like the prior list, the ordering here means little, aside from perhaps an attempt at semi-logical progression from introduction to the provider to wrapping up agreements.[1][2][3][4][5][6]

  1. What experience do you have working with laboratory customers in our specific industry?
  2. Can your solution readily integrate with our other systems and business processes, making it easier for our end users to perform their tasks?
  3. What is the average total historical downtime for the service(s) we're interested in?
  4. Do we receive comprehensive downtime support in the case of downtime?
  5. Where are your servers located, and how is data securely transferred to and from those servers?
  6. Who will have access to our data (including subcontractors), and what credentials, certifications, and compliance training do they have?
  7. Will our sensitive and regulated data be stored on a machine dedicated to complying with the necessary regulations?
  8. How segregated is our cloud data from another customer's, i.e., will lapses of security of another customer's cloud affect our cloud? (It typically won't, but asking the question will hopefully prompt the provider to better explain how your data is segregated.)
  9. Do you have documented data security policies?
  10. How do you test your platform's security?
  11. What are your policies for security audits, intrusion detection, and intrusion reporting?
  12. What data logging information is kept and acted upon in relation to our data?
  13. How thorough are those logs and can we audit them on-demand?
  14. For HIPAA-eligible data (e-PHI) we may have, will you sign a business associate agreement?
  15. What happens to our data should the contract expire or be terminated?
  16. What happens to our data should you go out of business or suffer a catastrophic event?
  17. Can we use your interface to extract our data when we want, and in what format will it be?
  18. Are your support services native or outsourced/offshored?

References