Overview
“With the adoption of cloud, procurement can be done independently from IT. The associated risks can be mitigated by facilitating rather than frustrating the business”
Where the CIO will make strategic choices regarding the cloud service providers (AWS, Azure, Google, etc.) and managed cloud service providers (parties that manage the cloud for the organisation), SaaS services can be purchased outside the sphere of influence of the CIO. Long-term commitments can be contracted, uncontrolled by everyone, with CSPs, for example in the form of reserved instances. ?
Licenses that are already used on-premises can also be used in certain situations in the public cloud. This results in significant discounts. The purchase and use of cloud services is straightforward and often no more than a credit card is needed to start. ?
Instead of banning or discouraging these initiatives, it is wiser to provide the organisation with knowledge and assistance regarding the procurement of these services. Armed with this knowledge, the organisation can optimise the procurement of cloud services. ICT and procurement can then work together and guide the organisation in making the right choices. Writing an RFP or specifications for SaaS purchasing requires specific cloud knowledge.?
Mapping the cloud landscape and contracts helps the organisation make the right choices on which SaaS solutions are needed, which are already in use and what are the conditions imposed by the provider, especially with regards to security. A SaaS purchasing checklist ensures that the most important points of attention are addressed in the future. ?
SaaS contracting involves more than just looking at costs and functionality. Data and application integration, security, data residence and exit options are important aspects that need to be assessed prior to closing a contract.
Activities checklist
Initial:
- Drawing up SaaS purchasing checklist?
- Making appointments around the purchasing process?
- Making an inventory of cloud landscape and contracts
Recurring:
- Guiding cloud procurement processes?
- Assessing SaaS candidates with regards to costs, functionality, security, integration options, data residence and exit options?
- Providing the organisation with knowledge and help in the field of cloud procurement?
- Tracking contracts and licenses in the cloud landscape?
- Monitoring potential functional overlap in the application landscape?
- Identifying shadow SaaS applications e.g. by using a CASB or investigate credit card reimbursements?
- Contracting the “illegally” used shadow SaaS applications
RASCI
| cloud consultant | responsible | transformation consultant | |
| cloud architect | supporting | cloud partners | |
| cloud security specialist | supporting | DevOps team | responsible |
| cloud developer | business stakeholder | responsible | |
| cloud engineer | architecture | informed | |
| cloud analyst | security | informed | |
| product owner CCoE | responsible | finance | consulting |
| management | procurement | accountable |