10.07.2015 Views

1E9Ct5D

1E9Ct5D

1E9Ct5D

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A. Use Only Reliable ProvidersWith technology as new as the cloud, it is difficult to ascertain whether a serviceprovider has a respectable reputation. Some providers, such as Microsoft, Google, andApple have deep roots in the IT field, whereas other smaller market-participants havenot yet earned a reputation at all. In order to meet his or her ethical duties, an attorneyshould consult with news sources, Internet search engines, and an IT specialist todetermine the reputations of potential service providers.B. Request Documents to Evidence Due DiligenceIn order to demonstrate that he or she has done their due diligence, the attorney shouldrequest copies of the prospective provider’s certifications from one of the agencies thatindependently audit the security practices of cloud providers. 46“Internationallyrecognized standards used by these auditors include: SSAE-16 (Statement onStandards for Attestation Engagements, the successor to SAS 70, Statement No. 70 ofthe Statement on Auditing Standards, Service Organizations), and SOC3,SysTrust/Webtrust.” 47By selecting and using a provider who has received one of thesecertifications, the attorney increases the likelihood that, if there was a dispute, theywould be held to have exercised reasonable care.46 Jayaratnam, supra note 18.47 Id.20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!