You are on page 1of 7

Lessons Learned From salesforce.

com Implementation Case Study


August 2013

SaaS in Financial Services


Trend: FS Institutions are increasingly embracing SaaS solutions Focus: Top business function migration candidates include CRM, recruiting, service operations, mobility, HR and IT operations

Speed bump: Sensitive and regulated data moving into the cloud remains hindered by concerns of adequate protections and regulatory adherence Benefit: Growth through improved customer insights, better customer service, effective collaboration, reduced IT costs, effective talent management, shorter time to market, improved agility and innovation
Copyright 2013 Accenture All Rights Reserved. 2

Is SaaS ready for FS?


Perceived Roadblocks Inadequate protection for financial services Data stored in unknown locations Regulated data should not reside in clouds Data not to cross borders Loss of control over data access Incident response confusion Compensating Workarounds Industry certified SaaS providers Specific contractual data residency requirements Safe Harbor facilitate cross border data sharing Technology control implementation Process and procedure collaboration

Copyright 2013 Accenture All Rights Reserved.

Case Study
The Organization
Large, private asset management company with offices around the world Enterprise decision to move to the cloud and employ SFDC

Security Concerns
General data protection regulations in various jurisdictions around the world Residency requirements Intellectual property protection

Desired a robust CRM platform without in- Client data protection house hosting to achieve fast time-to Protection of sensitive customer, business, market or IT information Deep integration with existing on-premise applications

Copyright 2013 Accenture All rights reserved.

From Requirements to Solutions


Considerations
Encryption vs. tokenization options Performance/network latency issues Search, sort, report, index capability hindrances

Solutions
Balance between enabling the business, time to market, and security Federated I&AM in order to integrate other cloud providers in the future

Monitoring capabilities
Search, sort, report functionality Logging functionality Malware detection

Copyright 2013 Accenture All rights reserved.

Extending Enterprise Security to SaaS - Framework

IP / DDoS / FW / IDS SAML for Authentication Manual security log export Deploy Federation Leverage Tokenization Integrate Monitoring / GRC

Data residency Audit / testing results Transparency Define Responsibilities Have explicit SLAs Account for regulations

trust.salesforce.com Security Implement. Guide 3rd party apps in catalog Joint Security Governance Integrated Incident Mgmt Enterprise API safeguards Test shared controls

SFDC offers
Copyright 2013 Accenture All Rights Reserved.

Recommended

Extending Enterprise Security to SaaS - Implementation Approach

1. Assess
Data for the cloud / sensitivity Enterprise security thresholds Applicable regulations Bestfit SaaS security solution / process

2. Implement
Technical framework

3. Monitor & Maintain


Compliance to organizational policies Insight into enhancements required to counter emerging threats Communication and reporting

Extension of existing technical controls to the cloud


Custom agreements defining shared responsibilities of client and SaaS provider

Copyright 2013 Accenture All Rights Reserved.

You might also like