Benefits and Pitfalls of Outsourcing Security.ppt
《Benefits and Pitfalls of Outsourcing Security.ppt》由会员分享,可在线阅读,更多相关《Benefits and Pitfalls of Outsourcing Security.ppt(27页珍藏版)》请在麦多课文档分享上搜索。
1、Benefits and Pitfalls of Outsourcing Security,Stan Kiyota, CISSP & CISM Senior Information Security Manager Booz Allen Hamilton, Inc.,Agenda,Outsourcing Definition Responsibility Keys for success Why? Who? What? Managed security service provider (MSSP) Definition Market trends, players Pros and cons
2、 of using an MSSP What to look for in an MSSP Key elements for managing outsourced security services Tips for successfully outsourcing security services,Defining “outsourcing”,Outsourcing: arrangement in which one company provides services for another company. These services are ones that usually ca
3、n be provided in-house but for one reason or another are not.,Audience Response,Raise your hand if you outsource some form of your IT services today.,Audience Response,Raise your hand if you outsource some form of your information security services today.,Outsourcing means you are still responsible,
4、You are responsible and held accountable; if something happens, responsibility rests with you. The outsourcing vendor should demand that you have an active role in management oversight.,These elements must come together for a successful outsource to occur,Business Policies &Legal Agreements,IT & Inf
5、ormation Security Policies,Service Level Agreements,Management Oversight,Your MSSP,Why outsource?,Cannot afford full-time info sec staff Cannot retain competent information security staff due to wages and market competition Have already outsourced other IT functions, why not information security ser
6、vices? Have already figured out that someone else can do it better, cheaper, faster than we can All of the above and more,Who outsources?,Businesses where IT security is not considered a core function of the business Commercial businesses up to $US1B in revenues; however, there are some multi-billio
7、n-dollar companies which have outsourced their entire IT functions to the likes of EDS and IBM Governments (Federal, State, Local),What services should I consider outsourcing?,Complete a business requirements analysis and determine the gaps between needs and capabilities. Determine what the business
8、 can support and what the labor market can bear. Ensure that your info sec architecture is complementary to the developing business plan for outsourcing. Document all services to be outsourced and policies, technologies, processes to support. Present a comprehensive business (not IT) plan for implem
9、enting managed security services.,What are “Managed Security Services” (MSS)?,Managed Security Services (MSS) offer onsite and remote monitoring and management of security services with 24x7 real-time monitoring, protection, escalation and response processes. Many of the managed services offered inc
10、lude: Firewalls intrusion detection systems (IDS) virtual private networks (VPNs) Routers antivirus/content checking periodic vulnerability or penetration studies/testing,Source: IDC,What is the market for Managed Security Services Providers (MSSP)?,Yankee, Forrester, Gartner, etc. have varied estim
11、ates of a $2B to $5B market for managed security services by 2005, to as much as $8B by 2008. Everyone is trying to play, but the vendor market is consolidating. MSSPs with 5 people are competing with companies with 50,000 employees.,Who are the players in the MSSP space?,TruSecure,LURHQ,In 2003, on
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BENEFITSANDPITFALLSOFOUTSOURCINGSECURITYPPT
