Lesson 9 — Outsourcing, Cloud, Architecture & Metrics
Outsource the work, not the accountability
A vendor can host systems, process data, administer infrastructure, operate monitoring, or implement technical controls. The organization can delegate tasks. It retains accountability/liability for its own data obligations.
Contracts should therefore address:
- service levels and security requirements;
- reporting and incident notification;
- right-to-audit provisions;
- consequences for failure;
- geographic/legal constraints;
- access, backups, breach response, deletion, and other responsibilities.
Cloud = shared-responsibility questions
Explicitly define who:
- secures infrastructure;
- controls identities and privileged access;
- encrypts data / owns keys;
- classifies data;
- approves vendor administrators;
- monitors access;
- removes/deletes data when the relationship ends.
Chain of custody must remain explicit across provider, subcontractor, partner, and downstream processor. An organization may even enter the cloud indirectly when a partner places its data there.
CRUD/CRUDE vs RACI
- CRUD/CRUDE → which role/process may Create, Read, Update, Delete, Execute data.
- RACI → who is Responsible, Accountable, Consulted, Informed for the process/control.
Data Security architecture
DMBOK describes Data Security architecture as the Enterprise Architecture component explaining how security satisfies business rules and external requirements. It shapes access, encryption, vendor/contractor use, Internet transmission, remote access, documentation, and breach reporting.
A mature traceability chain is:
Requirement → classification → policy → standard → role/entitlement → control → monitoring/log → audit evidence → metric → remediation
If a link is missing, security becomes hard to implement consistently or prove.
Five metric groups
- Security Implementation — are required controls deployed?
- Security Awareness — do people understand/follow expected behavior?
- Data Protection — are sensitive assets identified/classified/protected?
- Security Incident — what violations/attacks occur and how are they handled?
- Confidential Data Proliferation — how many sensitive copies/exposure points exist?
Metrics should be actionable and baselined. “50 alerts” means little without severity, trend, ownership, interpretation, and remediation.
High-yield metric clue
Excellent encryption does not eliminate copy risk. Hundreds of test/vendor copies still make Confidential Data Proliferation directly relevant.
Source anchor: pp. 249–255.