###### Buying Cloud: An Evolving Art

Buying cloud is an evolving art. The heart of the cloud business model - ala cart or consumption-based pricing, is an evolving beast. There still is no universal model for the buy-by-the-drink philosophy that is integral to the cloud value proposition. And the other key terms - those that really should be in what is euphemistically called a "Service Level Agreement" or SLA - are still largely ad hoc and vary across many government agencies.

GAO has sought to clear the air on this knotty problem. In April, it released another in its series of reports about the state of cloud computing within the federal government. This report catalogued the ten best practices that government customers should address when negotiating to procure cloud service offerings.

The list is important to cloud service providers - not the least because they can expect to see these terms in a growing number of cloud procurements. These terms will define the expectations and requirements between the cloud service provider and the government in terms of the nature, reliability and cost of the cloud service offering.

### GAO's Ten Key Best Practices
GAO identified ten key "best practices" for agencies to follow when negotiating an SLA. These involve such areas as:

1. **Define Roles and Responsibilities** - Always define the roles and responsibilities of the major stakeholders involved in the performance of the SLA and cloud contract. 
2. **Identify Key Terms** - Identify and explain key terms, including activation date and performance.  
3. **Define Performance Measures** - Define the performance measures of the cloud service, including who is responsible for measuring performance. 
4. **Access to Data** - Specify how and when the agency would have access to its data. 
5. **Management Requirements** - Specify management requirements, such as how the cloud service provider would monitor the performance of the cloud. 
6. **Disaster Recovery Planning** - Provide for disaster recovery and continuity of operations planning and testing. 
7. **Exception Criteria** - Describe applicable exception criteria for when the cloud provider's service performance measures do not apply. 
8. **Security Performance Requirements** - Specify the security performance requirements that the service provider is to meet. 
9. **Breach of Security** - Describe what would constitute a breach of security and notification processes. 
10. **Enforceable Consequences** - Specify a range of enforceable consequences, including terms for non-compliance with the SLA performance measures.

Applying these criteria, in its report GAO looked at existing cloud contracts across DOD; HHS; DHS; Treasury; and VA. It found that of the 5 agencies and 21 cloud contracts reviewed, 7 had fulfilled all 10 factors. The remaining 13 had incorporated 5 or more and only 1 failed to include any of these factors.

Cloud service providers doing business with the federal government should be prepared to address these key requirements if they wish to be successful at the negotiating table. Preparation with knowledgeable experts is essential to creating a fair and balanced relationship.

Cyrrus Analytics LLC

Hettinger Strategy Group

[1] “Cloud Computing: Agencies Need to Incorporate Key Practices to Ensure Effective Performance”, GAO-16-325 (April, 2016).
