Home > Ask the Security Experts > Security Management Questions & Answers > What are the risks associated with outsourcing security services?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are the risks associated with outsourcing security services?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 July 2007
Our company is looking to outsource services, including information security. What are the key pros and cons of relying on a service provider for information security, and are there any 'red-flag' circumstances when security shouldn't be outsourced?

>
EXPERT RESPONSE
I could probably write a book about the entirety of that question. But in an abbreviated nutshell, it's very important to tightly scope what you mean by "outsourcing information security." I've long held the opinion that nobody gets an award for doing everything themselves, so I'm a big fan of tactically outsourcing certain functions where an internal resource can't really add value. Something like email security or firewall monitoring are good candidates for that.

But I strongly believe that responsibility for the organization's information security program must reside internally. Security is a business function and thus the security program manager (let's call this person the CSO for argument's sake) needs to be on the ground internally to build credibility, be in the loop and relay the value of security to the rest of the executive staff.

It's not clear to me how an external party has the desire, capability or incentive to take full accountability for security. At the end of the day, I believe in the "fired doctrine." Meaning if something goes wrong, who is going to be fired? I doubt it's someone on the outsourcer's team, so it's pretty important to keep control of the security program internally.

Another analogy is whether you'd outsource the CIO. Even if the rest of the technology operation were moved to a service provider, you probably wouldn't -- so why would you outsource security program management?

For more information:

  • Application security expert Michael Cobb explains whether it's right for your organization to outsource email security services.
  • Visit SearchSecurity.com's Compliance School to learn more about compliance best practices across an extended enterprise.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    How are the PCI DSS deadline extensions affecting corporations' desire to become compliant?
    What are the roles of a liaison officer?
    Why are there still various independent credit card security standards?
    What is the best way to administer exams to students via computer?
    How can birth certificate fraud and passport fraud be prevented?

    Risk Assessment and Analysis
    Security data lapses hamper researchers
    Panel: IT governance, risk and compliance program helps reduce expenses
    Like MLB scouts, IT security pros are turning to metrics
    Google shares struggle to manage security complexities
    GRC Tools Help Manage Regulations
    Interview: Financial Services CISO David Pollino
    The New School of Information Security
    Penetration testing: Helping your compliance efforts
    Failure mode and effects analysis: Process and system risk assessment
    The pros and cons of data breach insurance

    Vulnerability Assessment
    Security data lapses hamper researchers
    Database patch denial: How 'critical' are Oracle's CPUs?
    Is attack code valuable for vulnerabilities or just a publicity stunt?
    Will the features of Windows Vista SP1 encourage wider adoption of the OS?
    Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
    How to install and configure Nessus
    Nessus: Vulnerability scanning in the enterprise
    Nessus 3 Tutorial
    Security Services: QualysGuard Security and Compliance Suite
    HP aims at IBM with application vulnerability scanning as service
    Vulnerability Assessment Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    risk analysis  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts