SaaS (Software as a Service), a.k.a. Software onDemand, is gaining momentum in many parts of the enterprise today. Many companies utilize SaaS for their customer/sales management, payroll processing, and even accounting, transferring the software development and maintenance for those applications to companies like Salesforce.com, ADP, and Intuit, respectively. SaaS can provide great TCO and efficiency benefits to companies since they no longer have to concern themselves with the development and IT expenses that go along with building and deploying these software applications. But as these business processes are outsourced, what happens to the risk?With in-sourced software, it’s clear — you build it and deploy it, you own the risk. If there’s a security vulnerability found, it’s your responsibility to fix it. Even with purchased software, you assume the risk of security holes that may be in software when you buy it. But when you use SaaS, do you include security clauses in your SLA (service level agreements)? What happens if ADP or Intuit is attacked and they lose YOUR payroll or accounting records? Are they responsible for your notification and damage control costs? Have you taken a close look at your SLA lately? I bet it has 3 pages of feature guarantees re. uptime and functionality and 12 pages of indemnification clauses, preventing you from seeking damages from your SaaS vendor. Which brings me to the question: Should the CSO have a role in making SaaS decisions? Does your company include security requirements as part of your SaaS decisions? Do you have remuneration options if there is a security breach and your sensitive data is lost? Related content opinion My Concerns with CyberSecurity Legislation no teeth, paper audits, and security auditors By Ed Adams Jan 06, 2012 3 mins Data and Information Security opinion Sony CISO Reporting to Executive Management. Maybe Cyber Security Czar will follow suit? By Ed Adams Nov 17, 2011 2 mins Data and Information Security opinion Sony appoints CISO in response to PlayStation attacks but reports to the CIO????? By Ed Adams Oct 28, 2011 2 mins Data and Information Security IT Leadership opinion Q&A with Myself - Thoughts on Sony, DOD, RSA, IMF & Lockheed Martin By Ed Adams Sep 22, 2011 3 mins Data and Information Security IT Leadership Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe