Risk Assessment



There are two primary risks of buying, leasing, or subscribing to the SalesForce system. One is the privacy issues; it includes IVK’s own confidential paper and the information of their staff. This would occur if IVK is under attack by a hacker or someone from IVK gives their files away. Their privacy rights might be violated. Also, the data of customers and suppliers have possibly been stolen by hackers. That will lead to the distrust between them.

Another problem is security which is a serious matter because SalesForce already experienced the outage several times. And their users cannot do anything during this outage. It’s no question this could be harmful to the users. Additionally, the misoperation or upgrade of software will cause the issue with losing data or system-breakdowns. So, there is still a risk in it although they have Data Safety detection.

It’s essential to have customers, employees, vendors and any other individual’s privacy safe with IVK. The potential privacy issues have two parts; both internal and external aspects. For the internal aspect, IVK should carefully think about the access right of the customer’s highly private information. The access right should be limited and approved by the director of the department. If customer’s information were accessible by every employee in the company, the information would be at a potential risk of exposure. In this case, we suggest encrypting partial customer data as well as other confidential information. In terms of the external aspect, Salesforce’s product and service doesn’t have issues of customer’s information exposed.  Therefore, the key point is internal decisions of taking care of privacy issues. IVK should limit the employees to access the complete information of a customer. Or assign the customers’ information management to different departments to avoid this issue.

While there has been lots of discussion about the vulnerability in cloud computing, SalesForce.com has invested in several layers of security for their clients. They use SSL, individual username’s and passwords, and hosts everything on a secure server with several layers of firewall protection. By using the two step identification at log in, Saleforce makes it more difficult for a virus like the heartbleed virus to gain access to data on the SalesCloud. Salesforce has an entire team dedicated to the security of it's customers. To read more visit: https://trust.salesforce.com/trust/security/ and http://www.salesforce.com/company/privacy/security.jsp

Given the risks as mentioned above, Salesforce is pretty safe when it comes to privacy and security issues. There are the potential risks of hackers and inside members at the IVK company releasing confidential data. The nature of what Salesforce does, is to provide customer information instantly to the sales team in order to build long lasting relationships among the potential clients. That is essentially what we need for the IVK Company in terms of a CRM system. Not to mention all of the other features that Salesforce offers (which IVK needs) since they are very valuable and beneficial as well. These beneficial features include:
  • Accounts & contacts
  • Task & event tracking
  • Outlook sync
  • Salesforce1 Mobile App
  • Content library
  • Customizable reports
  • Chatter — company social network

The chance of Salesforce being hacked into in relation to all of the benefits we are getting out of this CRM system is a pretty small risk as well as the risk of someone from inside the company releasing sensitive data. Since we are getting a lot of value from the use of the system, we are willing to take the small risk of it being hacked, but otherwise it is a pretty safe system to use.

3 comments: