It’s hard enough just to secure data and comply with legal requirements in your own infrastructure. It’s even harder once you move that data to the cloud, also known as Software as a Service (SaaS). SaaS is continuing to grow, and it will likely exceed on-location infrastructure soon, if it hasn’t already. In SaaS, a third party hosts the company software and data and also manages the infrastructure needs. In fact, companies usually install software that can access the third party host (usually a data center) through the Internet.
Compliance and SaaS
Some of the common compliance laws the companies need to meet depending on the services or products that they provide are:
- Sarbanes-Oxley (SOX)
- Gramm-Leach-Bliley (GLBA)
- Health Insurance Portability and Accountability Act (HIPAA)
- The Payment Card Industry Data Security Standard (PCI DSS)
There are also other federal and state laws that companies who are subject to the rules must meet.
Key SaaS compliance questions
Some of the compliance issues the SaaS provider must address are:
- What laws apply to the data center?
- What conditions apply to each law?
- Who has access or who might have access to the data in the cloud?
- How does the SaaS provider store the data on its infrastructure?
- What steps is the SaaS provider taking to prevent data breaches and exposure of the data?
- Who can access the data, and how?
- What authentication controls such as logins and passwords are in place, who creates them, and who has access to them? Are the credentials of workers who leave the company deleted?
- Some compliance laws require extensive audit trails. Both external sources, such as the SaaS provider, and your company may need to use these trails, so you may need to negotiate access to them.
Ask SaaS providers what security measures they take to prevent breaches, and what plans they have in place if a breach occurs, such as restoring data and notifying clients and customers.
If the SaaS provider uses servers or other tools that are in non- U.S. locations, then the SaaS provider will likely have to comply with the laws of those other countries.
Learn all you need to know about cloud service providers and compliance requirements
While keeping your infrastructure on a local network makes it easier to guarantee compliance, the cloud still offers many advantages. In addition, companies should review their compliance and security requirements with their cloud service provider. For help now, please contact Volico and speak with one of our knowledgeable representatives.
Discover how Volico can help you with your Certifications and Compliance needs.
• Call: (305) 735-8098
• Chat with a member of our team to discuss which solution best fits your needs.







