« May 2007 | Main | July 2007 »

June 2007 Archives

June 8, 2007

Security continues to be a key challenge for SaaS vendors

Jon Oltsik of CNet Blogs had an insightful post
titled - Software as a Service needs a strong foundation of security.
And I could not agree more. This is a key theme that is brought up in
our discussions with ISVs and end customers.



Jon mentions three key points and I quote:


  1. "SaaS vendors must become security beacons to succeed. These demands
    go beyond information and physical security; service providers will
    have to be familiar with their customers' business processes in order
    to understand where their services are most vulnerable. In my mind,
    "business process security" is the new frontier and SaaS vendors must
    blaze the trail.
  2. Data privacy is tantamount. Strong authentication, proactive
    auditing, and encryption must be a part of the SaaS design in order to
    restrict access to private and confidential data. The SaaS providers
    must assume liability for the cost and damages associated with any data
    breaches.
  3. SaaS vendors find security partners from the get-go. Managed service
    providers like IBM, VeriSign, and Symantec have a huge opportunity to
    be the Good Housekeeping seal of approval on SaaS offerings. As part of
    these big deals, SaaS vendors must transfer risk to security experts,
    use these partnerships for marketing advantage, and maintain their
    focus on solving business problems."



In addition, I would add the following:

  • It is not sufficient for the SaaS vendor to take a 'trust me'
    approach - they must be able to show the mechanisms and technologies
    they have put in place to ensure data security and privacy. For
    example, with Oracle Data Vault a SaaS vendor can ensure that the DBA
    will not be able to see the data and only manage and administer the
    database. This becomes even more important when the SaaS vendor relies
    on a 3rd-party managed hosting provider. The more the number of people
    one must trust, the less trustworthy the system is likely to be without
    using specific tools or methodologies.
  • User de-provisioning is very important. The truth is that the
    majority of data breaches take place by insiders or ex-employees. It is
    therefore important that the SaaS vendor be able to quickly disable (or
    de-provision) the user accounts when an employee leaves the company.
    This can be done in at least two different ways. First, the SaaS vendor
    can choose to use federation and rely on the customer to authenticate
    the user. Since each user is now authenticated for only a single
    session and the SaaS vendor does not have to explicitly disable access.
    The other approach is to put in place an Identity Provisioning system
    (such as Oracle Identity Manager) that allows SPML based provisioning
    of remote systems.
  • Think about auditing requirements upfront: It is important to be able to document
    the processes used for security and identity management for various
    compliance requirements. A system that allows you to explicitly model
    the business processes associated with security tasks such as user
    provisioning can help meet these requirements. Implicit processes
    cannot be seen or audited. BPEL is emerging as a standard language for
    modeling business processes.



It can cost a lot of time and money to bolt on security as an after
thought to your SaaS solution. Customers have repeatedly mentioned
security as one of the key hurdles to adoption of SaaS. A SaaS platform
that is designed for secure computing, such as Oracle, can help save on
costs and provide your customers with the confidence that Jon talks
about.



What are the security challenges you face as an ISV? If you are a user of SaaS, what concerns do you have?

(Update: You may want to check out this interesting post on Identity as a Service offering for Social Networking by fellow Oracle blogger, Nishant.)

June 20, 2007

eSeminar on SaaS

As part of our on-going conversations with the SaaS community of ISVs, hosters and other service providers, I will be doing an hour long seminar on SaaS. Here is a brief description of the the seminar:

Customers are increasingly asking for a wide
range of choices when it comes to deployment options including hosted
on-demand. In order to provide Software as a Service, you must deal
with a few key business and technical challenges including
multi-tenancy, service-level management, low TCO to scale, etc.


Join us for an informative 1 hour eSeminar highlighting Oracle SaaS
platform technologies, and find out how you can leverage these
technologies to build out SaaS applications either by SaaS-enabling
existing applications or introducing new services.

An
Oracle SaaS expert will describe the benefits of Oracle SaaS Platform
technologies to help you with the following common SaaS concerns:

  • Multi-tenancy
  • Security & Privacy
  • Service level Management

Given the 1 hour restriction and the broad range of audience from novice to  SaaS experts, we will spend some time on the basics - drivers, technology challenges, etc. and then dive bit deeper into a couple of specific challenges and Oracle's solution.

You can still register!

About June 2007

This page contains all entries posted to The SaaS Report in June 2007. They are listed from oldest to newest.

May 2007 is the previous archive.

July 2007 is the next archive.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type and Oracle