Inside Track: Outsourced security, outside views

There are many benefits with a managed security service, not least of which are useful outside perspectives, writes ALEX MEEHAN
Holistic approach
“Organisations must consider all elements of their information security, from basic firewalls to staff training and any managed services, holistically and recognise that it is a continuous journey”

Ward Solutions Pat Larkin, CEO

Ward Solution’s experience is that most organisations want to move at least one aspect of their information security to the as-a-service model. This covers a wide range including web or email protection, vulnerability or a more comprehensive secure perimeter solution. An advantage of managed security is that it can be done in the cloud, on premise or a hybrid combination of to suit the business.Organisations are outsourcing to managed security for a number of reasons such as in-house skills shortage, the growing trend of moving from a CapEx to an OpPEx model, flexibility, and cost reduction.

Businesses looking to move to the as-a-service model need to ensure the following:
1. Service Assurance – assure the service is fit for purpose and delivers on the core needs of your organisation
2. Supplier Assurance – similarly, the provider needs to be fully capable
3. Compliance – ensure compliance across your own organisation’s policies as well as legal policies such as data protection and revenue assurance
4. Onboarding and Offboarding – consider the information security lifecycle of your organisation. Can any integration or upgrade needed be easily onboarded, configured, managed and – if needed – offboarded?
5. Contractual Assurance – ensure the contract meets the needs of your organisation and justifies why you’ve migrated to a managed service in the first place
6. Plan B – Carry out a risk assessment and management plan for events such as the service or provider going out of business or any changes that might breach your compliance obligations

 

advertisement

 

At Ward Solutions, we recommend that Irish organisations consider all elements of their information security, from basic firewalls to staff training and any managed services, holistically and recognise that it is a continuous journey, not a destination that can be arrived at.

 

RELATED ARTICLES
Sign up for the
Technology Minute

Listen to Tech Radio

- Advertisment -

Most Popular

- Advertisment -