Skip to content

Lesson 9 — Outsourcing, Cloud, Architecture & Metrics

Outsource the work, not the accountability

A vendor can host systems, process data, administer infrastructure, operate monitoring, or implement technical controls. The organization can delegate tasks. It retains accountability/liability for its own data obligations.

Contracts should therefore address:

  • service levels and security requirements;
  • reporting and incident notification;
  • right-to-audit provisions;
  • consequences for failure;
  • geographic/legal constraints;
  • access, backups, breach response, deletion, and other responsibilities.

Cloud = shared-responsibility questions

Explicitly define who:

  • secures infrastructure;
  • controls identities and privileged access;
  • encrypts data / owns keys;
  • classifies data;
  • approves vendor administrators;
  • monitors access;
  • removes/deletes data when the relationship ends.

Chain of custody must remain explicit across provider, subcontractor, partner, and downstream processor. An organization may even enter the cloud indirectly when a partner places its data there.

CRUD/CRUDE vs RACI

  • CRUD/CRUDE → which role/process may Create, Read, Update, Delete, Execute data.
  • RACI → who is Responsible, Accountable, Consulted, Informed for the process/control.

Data Security architecture

DMBOK describes Data Security architecture as the Enterprise Architecture component explaining how security satisfies business rules and external requirements. It shapes access, encryption, vendor/contractor use, Internet transmission, remote access, documentation, and breach reporting.

A mature traceability chain is:

Requirement → classification → policy → standard → role/entitlement → control → monitoring/log → audit evidence → metric → remediation

If a link is missing, security becomes hard to implement consistently or prove.

Five metric groups

  1. Security Implementation — are required controls deployed?
  2. Security Awareness — do people understand/follow expected behavior?
  3. Data Protection — are sensitive assets identified/classified/protected?
  4. Security Incident — what violations/attacks occur and how are they handled?
  5. Confidential Data Proliferation — how many sensitive copies/exposure points exist?

Metrics should be actionable and baselined. “50 alerts” means little without severity, trend, ownership, interpretation, and remediation.

High-yield metric clue

Excellent encryption does not eliminate copy risk. Hundreds of test/vendor copies still make Confidential Data Proliferation directly relevant.

Source anchor: pp. 249–255.

← Lesson 8 · Next: Decision Rules & Readiness →