Industry


Ads by TechWords

See your link here


Michael R. Farnum's picture
Michael R. Farnum

Hitting the Security Nerve

Security Outsourcing - Is it time?

In my personal blog, I have been writing a series about how to be an effective security manager. In the first installment, I wrote about making yourself known to the executives and the general populace of the company by simply being social. In the third installment, I suggested sticking to the basics of security, like security-in-depth, risk management, etc. But it is the second installment that I want to pull from for this post.

 

In that post I advised that you make a list of all the things you do so you can get organized and to inform your boss and everyone else of the many responsibilities you have (the second reason may sound petty, but hey, somebody besides your dog needs to know how hard you work - and he's probably tired of hearing about it). The post listed a veritable smorgasbord of security admin / manager tasks. And it was not even near a complete list of all the things security practitioners have to get done to make their network secure.

 

When I look at that list, I have to ask the same question Alan Shimel asked: How many hours can you work in a day? I have slowly come to a very simple answer: not enough.

 

Take a look at the list I mentioned above. See if you could handle that load and not work 50-60 hours a week. Don't think so? Then what do you do? How can you get it all done and actually have a life? Well, I must say that I have been forced to re-think a position I have held dear for most of my IT career. I am starting to seriously take another look at.... outsourcing. GASP! SCREAM! (--cue Friday the 13th and Freddy music and lound end-of-the-world explosions here--)

 

Now before you get your knickers in a knot, I am not talking about firing a bunch of people but keeping them in their jobs long enough to train their replacements from some other country. I am talking about someone remotely managing some of your security assets. I am talking about giving up some lower-level security admin tasks to a third-party. Maybe monitoring the SIM, or opening and closing ports on the firewall, etc.

 

I know that this does not always fit well in a company. A dynamic company with a lot of changes really needs flexibility that most outsourcing firms will not be able to provide. But if you can afford some loss of flexibility, then it might work. And think about this fact: it also gives you an almost instant change control infrastructure (if the company does things right), which is always a major audit point.

 

I say it is worth looking into this option. I really don't like the thought of losing control (many firms don't allow you into the firewall once you turn over management - but that points back to the change control benefit). But the sheer volume of work makes it a bona fide alternative.

 

Think about it.

What People Are Saying

I agree with both Alan and

I agree with both Alan and C.J.

A MSP managing your firewall which is located in your cage/colocation space in a data center can take a big load of your hands, depending on how much gear you have colocated of course.

Then on the other hand, I would never suggest outsourcing other security functions, including anything residing on your internal network.

Its really a big toss up, It depends on the type of data thats being protected as well.

If you have basic web, app, and db servers, but you dont have confidential proprietary data in them, I think its perfextly safe to outsource the fw management to an msp.

IMHO there is never a good

IMHO there is never a good reason to outsource your security.

What you need to do is budget for the tools you need to make work more efficient. A good tool can replace a body. For instance, event log/syslog correlation management would keep your guys from having to login to device after device to view the logs combing for suspicious events.

You could spend $100K on tools and probably replace 2-3 full time salaries that might be over $100K each.

Just a thought.

Michael - While security

Michael - While security outsourcing to MSSPs has become more and more widespread, I think it is best for commodity type security functions. Most MSSPs do a decent job with firewalls. Some are doing IDS/IPS. Fewer still will do managed VM or SIM however. Those that do, don't usually use a best of breed product and have their own home grown solutions. If outsourcing means using less effective applications and technology, is it worth it?