text only

Cloud Stewardship Economics Survey

   

Your responses to this survey will be used in research that will influence the policy discussion in the area of Cloud Computing. We would like to thank you for taking the time to fill the survey in.

Background Information - All responses are anonymous

How happy are you with your IT?
 
 
 
 
 
 
Do you have a fixed frequency for IT investment?
 
 
   
 
   
 
   
 
   
How frequent ?
 
 
 
 
 
   
How often on average do you invest in IT
 
 
 
 
 
Do you consider outsourcing IT as a single function or do you distinguish for different application or business functions?
 
 
   
 
   
 
   
 
   
How old is your business?
 
 
 
   
 
   
 
   
How many employees do you have?
 
 
 
 
 
   
What is your annual turnover?
 
 
 
 
 
   
How many locations do you use?
 
 
 
   
 
   
 
   
Are your locations across national borders?
 
 
   
 
   
 
   
 
   
Are some of your locations outside the EU/EEA?
 
 
   
 
   
 
   
 
   

Information Security Handling

Do you hold information that would be considered commercially sensitive by you?
 
 
   
 
   
 
   
 
   
Do you hold, access or process information that your customers would consider commercially sensitive?
 
 
   
 
   
 
   
 
   
Have you ever assessed the impact a breach of confidentiality and/or availability would have on your businesses cash flow, profitability and reputation?
 
 
   
 
   
 
   
 
   

Which of the Following do you have Documented Within Your Organisation?

Do you have an information security policy?
 
 
   
 
   
 
   
 
   
Do you have a business continuity policy/plan?
 
 
   
 
   
 
   
 
   
Do you have a policy for choosing and engaging with third party suppliers?
 
 
   
 
   
 
   
 
   

Responsibilities

Who is accountable to customers, the legal system, regulators or any other third party outside of the business, should there be a breach of information security?
 
 
Who within your business is responsible for understanding and managing the information security risks which may exist when outsourcing business processes or systems?
 
 
How confident are you that you would know what questions to ask suppliers about their management of information security risks regarding your data or systems.
 
 
 
 

Supply Chain Risk Management and Information Assurance

If there was a breach of your businesses information confidentiality as a result of your suppliers' poor information security practices would you be prepared to invest the time and money to pursue them in a court of law?
 
 
   
 
   
 
   
 
   

On a scale of 1 - 5 (1 being most important, 5 being least) how would you rate the following impacts on your business resulting from a breach of information confidentiality and/or service delivery:

Service delivery
 
 
 
 
Information confidentiality
 
 
 
 
Do you assess what information security risks may exist when outsourcing a business process, system or engaging a third party supplier?
 
 
   
 
   
 
   
 
   
As you answered No, please identify a reason from the following:
 
 
As you answered Yes, would it be because of any of the following reasons?
 
 
   
Which of the following threats would you consider to be MOST important when looking to understand the risk when outsourcing a business process to a third party supplier?
 
 
 
 
   
What evidence of how a supplier manages risks to your information or information systems whilst in their possession  do you look for?
     
Terms & conditions of supply    
Data protection clauses    
Other data security clauses    
Termination of contract    
Data retention policy    
Jurisdiction Clauses    
Technology deployed    
Information and/or IT security standards implemented by supplier    
Right to audit a supplier    
We don't look for such evidence    
If a 3rd party supplier couldn't prove that they were following information security best practice would you still be prepared to do business with them?
 
 
If a supplier provided a demonstrably more secure service at a premium price would you be inclined to upgrade?
 
 
   
 
   
 
   
 
   
Are you using any external software services, sometimes called SaaS (software as a service) to help you deliver your business?
 
 
   
 
   
 
   
 
   
As you answered yes, what part of the business is using this:
 
 
 
 
 
 
   
Are you using any external IT hosting services, sometimes called IaaS (Infrastructure as a service) to host, support and maintain your IT infrastructure?
 
 
   
 
   
 
   
 
   

Cloud Services that You are Using

Are you currently using a Customer Relationship Management service provided via a web interface?
 
 
   
 
   
 
   
 
   
Are you using any externally hosted and maintained software, sometimes called software as a service (SaaS) to help support or deliver business processes. For example HR, payroll, sales and accounts.
 
 
   
 
   
 
   
 
   
Are you using any externally IT hosting services, sometimes called (IaaS) infrastructure as a service to host, support and maintain your IT infrastructure?
 
 
   
 
   
 
   
 
   

Many Thanks For Your Time

Please note down this password (case sensitive) for accessing the Cloud Migration Security document  Cloud Document Password: xw345fty

Please click on 'Submit' to be taken to your document

 
Toolbar background
  Snap Survey Software    
Toolbar background