This process is a good first step, according to an article in Tech News World, but more often than not, these organizations practice a “fire and forget” behavior. The article discusses why it is important to have due diligence and follow through in a cloud environment.
Organizations need to understand that its relationship with its service provider is not static, and neither are their services:
- Usage changes – the way you make use of a cloud provider
- Practices change – the way vendors and security teams operate
- Revisiting technical and non-technical evaluations
Some suggested evaluation processes were on-site audits and standardized questionnaires, which should be performed at frequent intervals.
Read through the whole article in Tech News World to see the author’s explanation and assessment as to why it is equally important to complete a thorough baseline assessment at the beginning and all throughout their relationship with their service provider.