SHARE
Facebook X Pinterest WhatsApp

Checklist: Make Sure Your SaaS Vendor Is Secure

SaaS brings with it a unique set of challenges for those responsible for security. Barmak Meftah, senior vice president at Fortify Software, says the most important shift is looking at your software vendor not as a product company, but rather as a service provider in a guest commentary over at our CTO Edge site. Sound […]

Written By
thumbnail
ITBE Staff
ITBE Staff
Mar 31, 2010

SaaS brings with it a unique set of challenges for those responsible for security. Barmak Meftah, senior vice president at Fortify Software, says the most important shift is looking at your software vendor not as a product company, but rather as a service provider in a guest commentary over at our CTO Edge site. Sound vendor management practices dictate that any third-party software is at least as secure as in-house packages, Meftah advises.

We’ve taken his checklist of steps to ensure that a SaaS vendor’s solution is secure and listed them in this handy slideshow, but do be sure to check out Meftah’s full column.
His final piece of advice? Remember that software is secure only when it’s built that way.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 1

Click through for nine key tactics for ensuring that security is built into your SaaS solution.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 2

Review the vendor’s service history, obtain customer references and ask them about their experiences with the vendor’s concern for privacy, reliability and security vulnerabilities.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 3

Be certain that application and infrastructure security requirements are written into your contract with any SaaS provider. Include an audit clause whereby you or a third-party can periodically verify that the required controls are in place.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 4

Get a solid Service Level Agreement (SLA). An SLA requires that the vendor provide a specified level of system reliability. A good vendor will strive for performance that meets Six Sigma levels of service quality (e.g., 99.9997% of security patches made within a set number of hours, not days, after public disclosure).

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 5

Do not accept a policy of making silent fixes to their service.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 6

Insist that the vendor’s own software development process adheres to a robust software development life cycle model that includes tollgates that check for secure coding standards.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 7

Carefully examine the vendor’s policies for data recovery and find out how long it will take to retrieve your data if you decide to terminate the contract, as well as how long it will take them to make it inaccessible online.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 8

Maintain strong encryption standards and key management for data transmission between your site and the vendor site.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 9

Be certain that your users are not the weak link in the security chain. Specify which Web browsers can be used to access services, and stay on top of browser security issues and updates. If possible, be certain that they must first log in to your network to access corporate information on the SaaS vendor site.

Checklist: Make Sure Your SaaS Vendor Is Secure - slide 10

Always maintain ownership of domain names and control domain access when services can be accessed by your users. That way, if you terminate a vendor relationship, you will not have to retrain your clients on the correct URL to use to find you.

Recommended for you...

DAOs: Why are They Important to Web3?
Tom Taulli
Feb 23, 2022
Web3: A New Catalyst for Enterprise Software
Tom Taulli
Jan 13, 2022
HP Life: How to Make Yourself More Valuable while Social Distancing
Rob Enderle
Apr 30, 2020
SAP Addresses Integration Issues
Mike Vizard
May 10, 2019
IT Business Edge Logo

The go-to resource for IT professionals from all corners of the tech world looking for cutting edge technology solutions that solve their unique business challenges. We aim to help these professionals grow their knowledge base and authority in their field with the top news and trends in the technology space.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.