With all the talk these days about cloud computing, SAAS, and ASPs, we see much focus on ensuring data entrusted to these vendors is adequately secured. This usually covers the first two letters in the well-known CIA acronym (i.e., Confidentiality, Integrity, and Availability), but the service levels for these vendors – the all important availability, response time, and other performance requirements – are frequently very thin. Given the recent, highly publicized downtime at several of the most well known vendors in this space, I thought it might be useful to highlight some of the key elements to be considered in drafting effective service levels agreements (SLAs):1. SLAs should be clear and absolutely objective. The vendor should be required to provide monthly reports on SLA performance. 2. Remedies (generally some form of credit) should be associated with each SLA. Remedies should escalate depending on the severity of the SLA failure (e.g., a 10% credit for availability between 99%-99.9 and a 20% credit for availability between 98%-99%). Repeated failures in a given time period should also cause escalation of remedies. All credits should be made automatically, without the need for the customer to request the remedy.3. Repeated failures (e.g., two failures in any four month period) should, in addition to all other remedies under the contract, give the customer the right to terminate the agreement. Repeated failures should also require the vendor to provide a root cause analysis of the failures and a specific plan to minimize future performance issues. 4. Broad force majeure exceptions to SLA performance should be avoided. While general Internet and infrastructure failures may be excluded, events such as strikes, power failures, labor issues, accidents, etc. should not. In particular, if a circle is drawn around the vendor facility providing the service, anything that happens within that circle, regardless of whether it constitutes an Act of God or not, should not relieve the vendor of its SLA obligations. You are buying a service. If the vendor fails to provide that service for any reason, there should be an adjustment in fees (i.e., the credit remedy mentioned above).5. Credits issued for SLA failures should not be framed in terms of “exclusive remedies.” The customer should have all other remedies available to it under the agreement, including the ability to declare a breach, terminate, and seek damages to compensate for poor performance. 6. Include the ability for the parties to meet and confer on at least an annual basis to evaluate existing SLAs and discuss potential changes. Related content opinion Finding Common Threads in Privacy and Information Security Laws. By Michael Overly Apr 26, 2013 3 mins Compliance opinion Ensure Your Data is Securely Deleted By Michael Overly Mar 11, 2013 2 mins Cloud Security opinion CIA in the Cloud By Michael Overly Dec 18, 2012 2 mins Cloud Security opinion Overreacting to Information Security By Michael Overly Dec 10, 2012 2 mins Privacy Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe