Home > Security Security Schools > Compliance School > Ensuring compliance across the extended enterprise > ISO 17799: A methodical approach to partner and service provider security management
Security Schools: Compliance School:
EMAIL THIS
 START   HIPAA   RISK   PCI DSS   PARTNERS & PROVIDERS   TECHNOLOGIES   COMPLIANCE 2.0   SOX PROGRESS   SOX BASICS   TOOLS   
Ensuring compliance across the extended enterprise

<< PREVIOUS | NEXT >>: Quiz: Ensuring compliance across the extended...
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

ISO 17799: A methodical approach to partner and service provider security management


Richard Mackey
06.20.2007
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip is part of Ensuring compliance across the extended enterprise, a lesson in SearchSecurity.com's Compliance School. Visit the Ensuring compliance across the extended enterprise lesson page for additional learning resources.

These days, it is fairly common for a company to outsource customer-facing services or allow another organization to handle data processing and even security monitoring and management. Outsourcing allows companies to provide a wider range of services, reduce cost and focus on other tasks that will strengthen the business.

Every time an organization trusts another business entity to handle sensitive information or manage critical infrastructure, however, there are risks. Worse yet, many companies do not realize that failing to closely examine their prospective partners' security practices can lead to compromise. Organizations that are bound by regulations like HIPAA, Gramm-Leach-Bliley (GLBA) and Sarbanes-Oxley (SOX) may pay an even steeper price, as these regulations explicitly require organizations to manage the risk associated with service providers.

Fortunately, enterprises can curtail partner or service provider security issues by taking a methodical approach to assessing and managing the risks. That means coming to terms with the risks and the costs of creating and maintaining these partnerships. One such approach is a partner management program based on the ISO 17799 standard.

A standards-based methodology
By definition, ISO 17799 is a "code of practice for security information management." In other words, it is a laundry list of best security practices that apply to a broad range of business environments. The standard covers areas including risk assessment, security policy, governance, access control, information classification, operations management and business continuity.

A partner management program based on the ISO standard consists of three phases:

  • Remediation, monitoring an


    d periodic assessments
    – After a partnership is established, the work is just beginning. Any important weaknesses that are discovered should be remediated according to an agreed-upon timeline. Furthermore, the initial assessment should be used as a baseline against which future analyses can be compared. Service providers should be revisited at least once a year to determine whether anything about their environments, designs or practices has changed for the worse. Using an ISO 17799-based report card makes it possible to compare a partner's progress with the results and assessments of other partners. The accumulation of information can help establish minimum requirements for all service providers.
  • ISO 17799 as a common framework
    While most service providers bristle at the idea of yet another security review, particularly one that goes to the depth that an ISO 17799 review calls for, most can appreciate the fact that the ISO standard provides a set list of requirements.

    One of the most problematic aspects of partner reviews is their ad hoc nature. Service providers are essentially asked to play by a different set of rules for each review they face. By agreeing on ISO 17799, service providers and consumers can substantially reduce the cost of preparations and make reviews much more efficient. The result is better communication, better documentation and faster consummation of service agreements.

    About the author:
    Dick Mackey is regarded as one of the industry's foremost authorities on distributed computing infrastructure and security. He has advised leading Wall Street firms on overall security architecture, virtual private networks, enterprise-wide authentication, and intrusion detection and analysis. He also has unmatched expertise in the OSF Distributed Computing Environment. Prior to joining SystemExperts, Mr. Mackey was the director of collaborative development for The Open Group (the merger of the Open Software Foundation and X/Open) where he was responsible for the integration of Microsoft's ActiveX Core with DCE and DCE Release 1.2. Mr. Mackey is an original member of the DCE Request For Technology technical evaluation team and was responsible for the architecture and defining the contents of DCE Releases 1.1 and 1.2. He has been a frequent speaker at major conferences and has taught numerous tutorials on developing secure distributed applications.

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Compliance Counselor,   Security Audit, Compliance and Standards,   ISO 17799,   COBIT,   Compliance School,   Ensuring compliance across the extended enterprise,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    << PREVIOUS | NEXT >>: Quiz: Ensuring compliance across the extended...
    VIEW ALL IN THIS CATEGORY

    RELATED CONTENT
    Compliance Counselor
    Common PCI questions: Web application firewalls or source code review?
    PCI management: The case for Web application firewalls
    The basics of enterprise GRC project management
    PCI DSS: The structure of a standard
    How to choose between source code reviews or Web application firewalls
    HIPAA compliance: New regulations change the game
    Data security best practices for PCI DSS compliance
    Key elements of a HIPAA compliance checklist
    A preview of PCI virtualization specifications
    Strategies for email archiving and meeting compliance regulations

    ISO 17799
    How to write a risk methodology that blends business, security needs
    IT auditing applications and tools for ISO 27002 certification
    Security survey finds increase in security standards adoption
    Mix of Frameworks and GRC Satisfy Compliance Overlaps
    GRC: Over-Hyped or Legit?
    Is the Orange Book still relevant for assessing security controls?
    How do ISO 17799 and SAS 70 differ?
    How to apply ISO 27002 to PCI DSS compliance
    How to migrate from SAS 70 to ISO 27001
    Should ISO 17799 play a role in risk assessment?

    COBIT
    Security survey finds increase in security standards adoption
    Mix of Frameworks and GRC Satisfy Compliance Overlaps
    GRC: Over-Hyped or Legit?
    Is the Orange Book still relevant for assessing security controls?
    Does SOX provision email archiving?
    COSO and COBIT: The value of compliance frameworks for SOX
    Mapping the path toward information security program maturity
    RSA Conference 2006
    Introduction to COBIT for SOX compliance
    How BS7799 and COBIT differ, part two
    COBIT Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    COBIT  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Research Solutions for Network Security, Access Control and Security Threats
    More Security Resources for Resellers, VARs and OEMs
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts