3 ms·
You need to know very little of this actually. EDIT: I will expand on this a bit. First, the real question you need to know, is, who owns the building your se
by patrickgzill 14y ago
You need to know very little of this actually.
EDIT: I will expand on this a bit.
First, the real question you need to know, is, who owns the building your servers will be in? Lots of people claiming to have datacenters are actually renting from someone else, or even sub-leasing from somewhere else, putting you 2 places away from the owner. As much as possible, get into a situation where your monthly payments go directly to the true datacenter owner.
Second, what about the network? Rather than engage in a lot of hand-waving, just find out who they are directly connected to.
Third, do they have both UPS and diesel genset backup for your power? If you are able to physically visit the place, have them show you the physical stuff.
Ignore the "Tier" datacenter and "SAS70" crap, Tier X != reliability and SAS70 is a load of BS (CPAs trying to soak up some consulting dollars - yes, an SAS70 report can only be prepared by a CPA firm...)
- Erwin 14y agoSAS70 -- that depends who you sell to I guess. Every major client we have that will put a bit of data on our servers asks about things like SAS70, physical security, environmental factors like power backup, disaster protection etc. etc. Mind you, I can't say for sure they'd not do business with us if we didn't have good answers, but SAS70 is something a big company cares about.
- dredmorbius 14y agoI disagree on the SAS70. Sure, it's an audit compliance document that does nothing of itself to ensure compliance. But: somebody asked and looked at this stuff, and there's absolutely no reason you can't do as much (or little) inspection as you want. Having been on a few DC audits myself, it's an educational process. And still ... onsite redundant generators, fuel, fuel provider contracts, backup batteries, etc., still mean little if there's a fault somewhere in the system (the past few major outages I've experience directly or have read about all included all of the above, but something somewhere failed to cut in or out appropriately). Nobody's got anything on the Krell though.
- patrickgzill 14y agoFair enough, but why can only CPAs perform such audits? It is spending $20K-$40K per audit for essentially nothing of importance. This cost gets passed on to customers.
- dredmorbius 14y agoI don't know that it's CPAs specifically. But it is essentially an audit/control document. Auditors are trained in, like, you know, auditing. Which is rather more than just beancounting, preconceptions notwithstanding.
- patrickgzill 14y agohttp://sas70.com/sas70_faqs.html http://sas70.com/sas70_faqs.html ; Question #2 - who can perform/sign off on audits? Only CPAs.
- dredmorbius 14y agoThanks. And again: what the audit entails is interviews, requesting and reviewing records, and the like. This doesn't guarantee that a SAS70 site is doing what it says it's doing. But if there are gross inconsistencies in the statements and documents, they should stand out. From there, use the SAS70 report as a basis for your own questions. There are some very good summaries of things to as at sites such as ServerFault, WebHostingTalk, O'Reilly, and elsewhere. If the SAS70 report says that all access is controlled, but you find you're able to casually stroll through the main door ... something's not adding up. Dig deeper.