Information Security in System OutsourcingNovember 6th, 2007
FiledNovember 6th, 2007Outsourcing agreement is a document to specify the relationship between outsourcing partners; service provider who offers the outsourcing service and client whose system is to be outsourced. A major success factor of the outsourcing is clear and comprehensive specification of duties and responsibilities regarding to information security. As the outsourcing agreement is juridically binding, service provider is responsible for acting accordingly. Therefore, the agreement is where security Measures should be agreed upon. As there is no clear understanding of contents of an adequate security specification in outsourcing agreement, this paper identifies the critical components and studies the issue of how to set requirements for outsourcing service providers and control enforcement of these requirements.