Home > Ask the Security Experts > Application Security Questions & Answers > What are the pros and cons of outsourcing email security services?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are the pros and cons of outsourcing email security services?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 May 2007
Would you recommend outsourcing enterprise email security? What are the pros and cons when hundreds or thousands of users are involved?

>
EXPERT RESPONSE
For the vast majority of enterprises, there is a strong business case for outsourcing email services. Enterprise-scale email infrastructures use uptime and resources, and email security has become an ever-increasing challenge. Many enterprises have already outsourced email to reduce their overall messaging costs. Leaving their IT departments to focus on core competencies, these companies have also improved reliability.

A well-planned move to outsourced email security service should allow most organizations to reduce capital costs, achieve predictable costs, as well as improve performance, reliability and security. An obvious advantage of using such a service is the convenience of having someone else manage messaging processes and infrastructure associated with message filtering, delivery and the elimination of spam-related network traffic.

Another advantage of email security outsourcing is its relatively easy implementation. Outsourcing doesn't require on-site equipment or third-party access to private servers and networks. Setup usually just involves changing a domain name system's MX (mail exchange) record to point to the service provider's mail gateway.

Such an arrangement also provides a side benefit: your email servers will be protected from denial-of-service attacks. If your mail server only picks up mail from the service provider, all DoD mail attacks will have been filtered and handled by the service provider's defense infrastructure. Also, because filtering is performed outside of your own network, it won't interfere with your perimeter defense devices. With outsourcing, it's often easy to avoid over-engineered systems. In many cases, the services can be scaled to current usage requirements.

When reviewing possible service providers, you must verify that the service level agreement (SLA) is going to deliver the security, reliability and costs that you require. A good email service provider should offer the following:

  • Anytime, anywhere, reliable access to email
  • Load balancing and a fully redundant infrastructure
  • A wide range of messaging features such as webmail
  • Filtering of incoming mail for viruses, spam and inappropriate content

    I would also look for a provider who offers outbound message cleansing and policy enforcement. Secure connections are also important so that encrypted email pathways can be set up between offices and business partners.

    So, are there any downsides to outsourcing? Some organizations may feel uncomfortable losing control over some of their infrastructure. A service provider does add another hop to the email chain, and that may cause concern for some, since email is inherently insecure. My opinion is that outsourcing email is no more or less risky than using an ISP or using mail delivery services such as FedEx or UPS.

    However, there are the risks that exist in any commercial relationship. How financially stable is the provider? How easy would it be to move to another provider or bring email back in-house if you weren't happy with the outsourced service? As with any outsourcing decision, you must do proper due diligence when choosing from one of the many outsourcing services. You should try to find a provider that will protect against such issues.

    More information:

  • Learn how to maintain compliance when outsourcing enterprise services.
  • Visit Messaging Security School and review email security basics.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    Protecting exposed servers from Google hacks (and Google 'dorks')
    Which automated quality assurance tools can be used to test software?
    Has proof-of-concept mobile device malware translated into any meaningful attacks?
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?
    Which operating system can best secure an FTP site?
    Will firewall technology have to adapt to applications that use port 80?
    How secure is a mobile phone platform that has an open source framework?
    What ports should be opened and closed when IPsec filters are implemented?

    Email Security Basics
    Secure messaging complications result in limited protection
    Podcast: Exchange security -- A quick primer
    Are Internet cafe users' email credentials at risk?
    Enigmail: Wrapping email in a digital security blanket
    Email authentication showdown: IP-based vs. signature-based
    Are challenge-response technologies the best way to stop spam?
    Researchers flag Symantec Mail Security flaws
    Serious Google Gmail flaw exposes sensitive user data
    Will only allowing whitelist email messages stop image spam?
    How is internal mail channeled through an enterprise firewall?

    Creating and Managing Information Security Policies
    Security Awareness Training Essential Part of Infosec Program
    How to lock down instant messaging in the enterprise
    Worst practices: Bad security incidents to avoid
    Thompson calls for marriage of data and security management
    Companies Collecting Too Much Customer Data Increase Exposure
    Interview: Arizona CISO David VanderNaalt
    Incident response success in five quick steps
    Social networking Web site threats manageable with good enterprise policy
    IT GRC: Combining disciplines for better enterprise security
    Security management in 2008: What's in store
    Creating and Managing Information Security Policies Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    anonymous email  (SearchSecurity.com)
    asymmetric cryptography  (SearchSecurity.com)
    challenge-response system  (SearchSecurity.com)
    cipher  (SearchSecurity.com)
    cipher block chaining  (SearchSecurity.com)
    plaintext  (SearchSecurity.com)
    steganography  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts