3
5 Comments

Outsourcing development and securing technology assets. Best practices?

Hi everyone!

What are the must-dos or best practices when collaborating with contractors regarding securing your technology assets?

An example of a situation would be non-technical founder outsourcing the development and deployment of an application to a contractor. After the work has been successfully concluded to both parties satisfaction, what can be done to ensure that application will be safe and functional moving forwards - from a potential sabotage or security standpoint?

Domains? Servers? Codebase? Payment processing?

What should be done by the founder before hiring a contractor? Whilst working with a contractor? And after?

Thanks for your time

  1. 1

    This is a big question. I'm going to write a long-form piece to answer it as completely as I can. I'll comment back here when it's done.

      1. 1

        Thanks, I'm reading it now. I appreciate you taking the time for this!

        I will reply here with any follow up questions!

  2. 1

    Fragmentation. Don't give the work to any single entity. As devs come and go, change passwords. Use a WBS and assign tasks to different teams. Create code reviews, and use a bug base. If non technical, hire a technical manager. My teams have built many successful SaaS products offshore. Send me a PM.

    1. 1

      What about if initially all the development work will be handled by a single individual?

      Also, what is a WBS?

      Thanks for the help.