Following up on my comments last week on the need for service level agreements (SLAs) to ensure data availability in hosted environments (e.g., ASPs, SAAS, cloud environments, and other online services). This week some further suggestions and considerations for SLA:1. Not all SLAs should be looked on as punitive. In many instances, businesses have achieved excellent results and return on their investment by offering incentive payments for vendors who exceed SLA requirements. 2. Another type of positive incentive is the use of language permitting the vendor to “earn-back” credits for previous SLA failures. For example, if a vendor suffers an availability failure in one month for which a credit is assessed, but corrects the problem and has no further availability issues in the two months thereafter, the earlier credit is erased.3. As a matter of goodwill, language should be considered permitting the customer to waive SLA credits in selected circumstances. For example, if a vendor is working hard to resolve a situation and has otherwise been performing adequately, it may make good business sense to waive an applicable credit. Waiver, of course, in a particular instance would not result in the waiver of any future SLA failure. 4. Although not directly related to availability, other relevant SLAs should also be considered. For example, response time requirements to ensure an acceptable user experience or specific SLAs for the time to recover backups from off-site storage. In offshore engagements, where staff turnover is sometimes in the double digits, data is placed at risk simply by the sheer number of personnel rotating through the vendor’s facilities. In these cases, consider adding an SLA imposing credits if staff turnover exceeds a certain threshold. Related content opinion Finding Common Threads in Privacy and Information Security Laws. By Michael Overly Apr 26, 2013 3 mins Compliance opinion Ensure Your Data is Securely Deleted By Michael Overly Mar 11, 2013 2 mins Cloud Security opinion CIA in the Cloud By Michael Overly Dec 18, 2012 2 mins Cloud Security opinion Overreacting to Information Security By Michael Overly Dec 10, 2012 2 mins Privacy Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe