PAKISTAN CLOUD FIRST POLICY
10.2 Contracts with CSP
The relevant Cloud Office will issue guidelines for the execution of cloud computing contracts between
PSE and CSP. These guidelines will cover (but are not limited to) the following areas: -
10.2.1 Service Level Agreements (SLA)
SLA are undertakings that are binding on the CSP on the service level. Among other things, they
stipulate penalties for the CSP if the contractual undertakings are not fulfilled. They are particularly
important with regards to clauses on security (vulnerability scanning, patching and change management,
quality control checks, certification requirements, etc) and data protection (retention period, exercise of
rights of data subjects, availability of processing, etc.).
The provisioning of cloud solutions by CSP shall be governed by SLA by specifying and clarifying
performance expectations and establishing accountability. The SLA shall relate to the provisions in the
contract regarding incentives, penalties, escalation procedures, disaster recovery and business
continuity, and contract cancellation for the protection of customers in the event the CSP fails to meet
the required level of performance.
PSE shall closely monitor the CSP compliance with key SLA provisions among others on the following
aspects:
a.
b.
c.
d.
e.
f.
Availability and timeliness of services;
Confidentiality and integrity of data;
Change control;
Security standards compliance, including vulnerability and penetration management;
Business continuity including disaster recovery and contingency plans; and
Help Desk Support.
10.2.2 Interoperability Requirements
PSE shall require interoperability of the components of cloud infrastructure to work together to achieve
the intended result based on international standards. The components may come from different sources
including public and private cloud implementations. The components shall be replaceable by new or
different components from different CSP and continue to work, to facilitate the exchange of data
between systems.
10.2.3 Migration between Cloud Service Providers
PSE may decide to change / migrate between CSP for a variety of reasons. Their initial migration to
the cloud must facilitate future migration between platforms. This can be enabled by defining
technology standards in their procurement processes. If PSE build their infrastructure using standard
and widely available components, this will facilitate the migration of their data to the cloud and between
CSP. PSE shall consider the necessity of migrating potentially large quantities of data to launch a
service, and the ability to increase the scale if necessary. CAO will be available to facilitate in
recommending models and roll out plans for PSE to follow for cloud adoption and migration between
CSP.
10.2.4 Data Ownership
PSE will have full ownership of their data. They will decide how and where their data is stored and
managed. Data kept on the cloud remains the property of the PSE irrespective of who owns, manages,
or operates the cloud. PSE has the right to access, retrieve, modify or delete the data irrespective of the
physical location of the cloud. It also has the right to approve, deny or revoke access to the data by third
parties.
Page 14 of 21