Educause Security Discussion mailing list archives

SLA for Non IT Managed Server?


From: Kris Monroe <kmonroe () ITHACA EDU>
Date: Tue, 12 Apr 2011 20:00:49 -0400

Anyone have something like an SLA that they require by signed by a non IT owner of a server? For example, a Faculty member that wants to host a web server and a database server to support their research project. I could see the SLA outlining the faculty member is responsible for patching (OS, web server, database), hardening, limiting the database to the one they have discussed (that has no PII), is responsible for user accounts (including provisioning/deprovisioning), etc. And that changing of the agreed upon use requires a new or revised SLA.
Thanks in advance!
-Kris

--
Stay Safe Online!
Visit ithaca.edu/ICinfosec for the latest cyber security tips.
--
Kris Monroe, CISSP, CISA
Information Security Officer
Ithaca College

email: kmonroe () ithaca edu
P: 607.274.1997


Current thread: