Home > Security Tips > Compliance Counselor > Six essential security policies for outsourcing
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Six essential security policies for outsourcing


Kevin Beaver, CISSP
04.05.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Regardless of how you feel about it, odds are you'll eventually have to outsource some type of IT service. Having seen both sides of the IT outsourcing issue, I've found that practically every organization needs a minimum set of security policies to help reduce its inherent risks. It's easy to read this and say, "I trust my IT provider" or "we really don't have any issues here," but it's not about whether or not you can count on and trust people; it's about doing the right thing for the business -- to make sure the proper protection mechanisms are in place to reduce risk.

Here are six essential security policies for dealing with external service providers. You can create separate policies for each, integrate these into your existing policies or create a single outsourcing policy that addresses each of these areas.

1. Acceptable usage
This is one area where employees are often covered by policy, but outsiders are overlooked. Make it policy for anyone connecting to your network to abide by a reasonable set of rules – no offensive material, no unauthorized security testing tools, no copyright violations, no unsecured wireless systems, etc. Consultants, auditors, systems integrators – anyone plugging in – can easily introduce security risks and liabilities. Make sure those that connect to your systems, especially auditors and contractors who will be working with you for an extended period of time, know what is not acceptable usage. The more enforcement technologies you have in place, the less effort you'll have to expend and the more transparent you can make the enforcement process. A smart way to create a controlled environment is to loan these users one of you...



r organization's computers.

2. Information access
An information access policy begins with a solid information classification system. Outline the information that can and cannot be shared with or accessed by external providers. It's likely that anyone accessing critical servers is going to come into contact with your most sensitive information. Make sure those granting access are aware of this policy so they only grant the minimum necessary access to get the job done.

3. Information destruction
Given that information -- both hard and soft copy -- leaving your organization in an unauthorized fashion is one of your greatest vulnerabilities, be sure to pay special attention to this area. Make it policy and include it as part of any confidentiality or non-disclosure sections in your contract with third-party providers. Require that all information is either returned to you or destroyed.

4. Hiring and termination
Setting up a computer and/or network account for a new consultant or technician shouldn't be taken lightly (although it usually is). Again, follow the rules of need-to-know and minimum necessary, and by all means, make sure the account(s) get disabled the minute the user no longer needs access. Don't forget about any other administrator-level passwords -- such as for routers, local admin accounts and Web applications -- that you may have had to divulge in your dealings with outsiders. If possible, change the passwords when the project is complete.

5. Removal of property
The important factor to remember here is that any equipment, media or hard copy information, such as a laptop, hard drive or network diagrams, taken offsite is out of your control and needs to be properly protected. Make it policy that this property is kept protected at all times and returned when the project is complete.

6. Minimum computer requirements
Another serious vulnerability is allowing a third-party computer on your network without ensuring that it's properly protected and clean of any malware such as viruses and spyware. Make it policy to require any outside computer plugging into your network to have up-to-date patches, antivirus signatures, real-time malware protection (meaning viruses, etc. are continuously being checked for in memory, e-mail, Web browsing, etc.-- not just during hard drive scans), and even personal firewall software if deemed necessary. This is especially important if you provide remote access through a VPN, Citrix, Terminal Server and the like, since third parties can pretty much connect via any insecure computer they want. All it takes is one infected or insecure computer to completely open up your network to the outside world -- a risk no one can afford.

If your organization takes security policies seriously, it should be easy to integrate these outsourcing-related policies into your environment. I'm not a lawyer, so definitely run all of this past your legal expert before putting it into action. Finally, make sure everyone dealing with external IT providers is aware of these policies (network administrators, security managers and even purchasing/procurement) to make sure you get the most out of them.


RELATED INFORMATION:
Kevin Beaver is an independent information security consultant, author, and speaker with Atlanta-based Principle Logic, LLC where he specializes in information security assessments for those who take security seriously and incident response for those who don't. He is author and co-author of several information security books including Hacking For Dummies and the upcoming Hacking Wireless Networks For Dummies, both by Wiley Publishing. Kevin can be reached at kbeaver@principlelogic.com.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Application and Platform Security,   Enterprise Vulnerability Management,   Vulnerability Risk Assessment,   Enterprise Data Protection,   Enterprise Data Governance,   Information Security Policies, Procedures and Guidelines,   Information Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
Benefits of ISO 27001 and ISO 27002 certification for your enterprise
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders
PCI DSS compliance requirements: Ensuring data integrity
Understanding PCI DSS compliance requirements for log management
Are 'strong authentication' methods strong enough for compliance?
Strategies for using technology to enable automated compliance

Vulnerability Risk Assessment
What patch management metrics does Project Quant use?
Screencast: How to launch an OpenVAS scan
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
Newest malware threats
Are Web application penetration tests still important?
PCI compliance requirement 6: Systems and applications
Cybercrime and threat management
Vulnerability Risk Assessment Research

Enterprise Data Governance
How to protect distributed information flows
Interpreting 'risk' in the Massachusetts data protection law
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
gray hat  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts