Outsourcing Information Security
When it comes to the outsourcing of information security functions specifically, the situation is even worse. Far too few organizations know the inherent risks involved with outsourcing security, and don't properly investigate what they are getting into. The same company that makes it nearly impossible for an employee to enter the office supply closet to get much needed toner cartridge will outsource their intrusion detection, email and firewall systems without a blink.
One of the many reasons companies turn to security outsourcing and managed security services providers (MSSP) is to use their limited internal security staff for more interesting areas such as web development, VPN and e-commerce applications. They will then outsource the boring activities such as firewall and IDS monitoring and maintenance to a MSSP.
Given that activities such as firewall monitoring and administering an IDS in large enterprise requires 24/7 support, it is not unusual for a company to want to outsource such activities; monitoring and administering are not core functions of most organizations.
The trouble comes from the lack of due care often given to choosing a MSSP. With that, Outsourcing Information Security is a long-overdue book that asks the questions that are necessary before an organization decides to outsource any information security function.
The author's general tone is against the outsourcing of information security; but provides readers with the various benefits and risks involved in outsourcing security, and let's them ultimate decide if outsourcing security is right for their organization. It is the reader who must define, evaluate and manage those risks and determine if outsourcing is a viable solution. These include technology, business and legal risks.
The book comprises nine chapters and three appendices totaling a bit under 250 pages. The first two chapters provide a good introduction to and overview of outsourcing and information security, and the associated security risks.
Chapter 3 details various reasons why outsourcing information security makes sense. The chapter includes various tables and references to the many reasons why a company would want to outsource security.
Chapter 4 takes the other side and analyzes the risks of outsourcing. The chapter details the traditional risks, in addition to other factors such as hidden costs, broken promises, phantom benefits and more. The book shows that while many organizations hand over information security responsibility to their MSSP, when things go wrong, they can't effectively blame the MSSP. When things go wrong -- and they will -- all of the fingers in the world can be pointed at the MSSP, but the ultimate responsibility falls on the organization itself. With outsourced security, if something goes wrong, those fingers will point back to the company's security manager, not the incompetent firewall administrator in Bangalore.
The chapter provides a balanced look at the risk of outsourcing, and while calm in its overall approach, the chapter should at least make the person considering outsourcing information security think twice. In fact, the author concludes the chapter by stating "when all of the risks of outsourcing are considered, one wonders how anyone ever makes the decision to use a third party." Nonetheless, there is plenty of evidence that many security activities are indeed outsourced to MSSP, and are often satisfactory from both the buyer's and seller's perspective.
Chapters 5 and 6 provide a thorough summary of the costs and benefits of outsourcing, and provides a method with which to categorize them. The chapter is well suited for a CFO with its discussion of direct vs. indirect costs, controllable vs. non-controllable costs, and much more. These two chapters show that creating meaningful financial numbers to see if outsourcing makes financial sense is not such an easy task. It is important to understand that outsourcing sometimes makes financial sense, but certainly not all the time. For those organizations that don't crunch the numbers seriously at the beginning, these costs can later come back to haunt them in a big way.
Chapters 7 and 8 detail the processes involved in commencing an outsourcing project, from requirements gathering to placing policy against the outsourced company. A mistake many organizations make is failure to ensure that the MSSP is abiding by the client's information security policies, rather than their own.
Similarly, one of the most overlooked areas of outsourcing information security functionality is regulation. A U.S. company may be under numerous regulations, from HIPAA to Sarbanes-Oxley, GLBA, SEC and more; when they outsource their security functionality, the remote technician may not be under the jurisdiction of the SEC; but the corporate data still must be protected according to those regulations.
The main part of the book concludes with chapter 9, which provides a 20-step process to determine if an outsourced security solution is appropriate. In seven pages, the author specifies the various events, tasks and steps that make up the typical outsourcing project.
Appendix A provides a breakdown of the various services that can be outsourced, with Appendices B & C providing brief histories of IT Outsourcing and Information Security.
The only downside to the book is its $85.00 price, which is at the high-end for technology and business books. While the price is high, the book is a huge value for anyone considering outsourcing security. The book asks the questions that are often never asked, and details how the outsourcing of information security is not the slam-dunk that the MSSPs often portray it to be.
For those who know what their security issues are and look to outsource their security functionality to a trusted MSSP, Outsourcing Information Security shows how it can be done. On the other side, for those who are drunk with the panacea that outsourcing security is supposed to provide, Outsourcing Information Security will be a sobering wake-up call.
You can purchase Outsourcing Information Security from bn.com. Slashdot welcomes readers' book reviews -- to see your own review here, carefully read the book review guidelines, then visit the submission page.
serves them right. keep it in america!
To me all the outsourcing problems can be resumed to a simple allegory : cooking.
Home-cooked and cafeteria; sure you'll eat just fine at the end of the day, but chances are the cafeteria food will taste bad, cost less in the short term (efforts + money) but more in the long term, and doesn't have the nice 'home' feeling.
And you're never sure if the cook is on a bad day and spit in your soup (security allusion, for those who don't get it).
Eureka Science News - automatically updated
cannot be complete without chapter 11.
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
Let's hope that this opens the eyes of some american corporations, as a person looking for work in the IT sector, it sure wouldn't hurt to have an influx of jobs.
You can pick your nodes, and you can pick your friends, but you can't pick your friend's nodes
My President says so.
If you want to protect yourself, always ask your bank, medical clinic, etc. whether it outsources information processing to China or India. If the answer is "yes", then find another place to do business.
This is FUD, plain and simple. Outsourcing has happened and will continue to happen. Proper precautions must be taken in any business decision, but it is naive and sophmoric to eliminate outsourcing as an option based on the fears presented by the autor.
Those books should be pretty secure on the bookstore shelves.
That aside though I think its about time people quit whining about how inherently evil outsourcing is. Many companies outsource everything from cleaning and security to payrole and management advise.
Of course if you outsource security there is a risk, just the same as you risk one of your own employees fucking you over if you keep it in house. Proper investigation and dilligence are required. Thats not to say outsourcing is an inherently bad thing. In many cases companies will gain from outsourcing to specialist companies who can offer greater competency than could be achieved inhouse.
Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
What truth?
There is no dupe
Ask yourself this. Were do you want your secrets to reside?
Who do you trust to watch them?
No matter where the seed lies now a days companies have gown much bigger than the nation itself. Companies have become multinational trananational and their products and suppliers are all intetwined spanning multiple countries. So like it or not work is also going to be distributed and spread over many nations. Protection of intellectual properties and the like has to be developed within the organisation in consultation with the service provider or third party vendors. Taking an lazy outsiders look into the internal workings of an multinational company will not help to understand the extent of globalisation in every activities.
Didn't I say the same thing a few months ago and get modded troll? I find it hard to believe stuff like this is just now coming out. It isn't new news. Even Dell starting pulling back from overseas when they made the same realizations many of us said would happen with the language/time zone/distance barrier.
Two roads diverged in a wood, and I - I took the one the bus load of girls just went down.
Rather than saving money, many organizations have found that outsourcing ultimately is much more expensive than keeping security functions in-house
Slashdot hates outsourcing.
Period
Geez - that is alot of words to say management doesn't get lobster from the outsourcer's sales team and the job might get done if in house.
Contrary to popular belief there is not a cracker/hacker/meanie in the world that actually wants to steal your data. Data is worthless. There is not a single market for it, even stuff that seems to be really valuable.
"But but but, I have lots of top secret plans for our X14 prototype for the new product line..."
Nope, Not Interested. The data on your new product line is a trade secret, and even if your biggest competitor didn't already think thier own product is superior, being caught with the data could cost them thier entire business.
"But but but, I have information on the new merger!"
Nope, same deal. Getting caught by the SEC means JAIL TIME for rich white men. They don't need that. Your competitors do NOT want to see your information.
"But I have millions of credit card numbers!"
So does google.
"But I have..."
No, nobody wants your data, get that through your head!
What they DO want, however, is your hardware. The VAST majority of hacking occours because someone wants to own your machines so they can be used as zombies in DDOS attacks and to send spam. Forget about protecting your useless data, but SECURE YOUR MACHINES, damn it.
Do it yourself, or pay someone else to do it, since when did either case not involve doing your homework properly? The only bad thing about outsourcing security is that managers think they can get away with doing less homework than doing it in house. Otherwise, it's a perfectly valid option.
There is a big debate in Canada about outsourcing to US based companies due to the fact that the Patriot Act allows the FBI access to databases. Canada has fairly strict privacy laws and the liability of sending this information to the US could be big since there is no way for a US company to refuse the FBI access. The British Columbian government is still thinking of going ahead with sending of medical information down to the United States. It should be an interesting election day issue come next April when the voters go to the polls for the local elections...
Even Canada do not want it's private information in US hands.
Comment removed based on user account deletion
Sorry, the joke was just waiting to be said.
But the second one starts preaching the increased unemployment here, or the poor conditions there, I walk away...
In Soviet Washington the swamp drains you.
Is it just me iris this author in the wrong line of work? Axelrod? Are you kidding me?
A damned good reason to not let multinational companies import and export across American borders anymore if you ask me.
SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
You know the name of the first multinational company?
East India Company.
They landed in India to sell guns and ended up ruling the subcontinent for two centuries.
The cycle has to complete.
sounds redundant to me.
Although I think offshoring will eventually gut our economy[*], if a company is going to offshore, then they should do it more effectively. Communicating business requirements to offshore teams can be tricky and time-consuming in itself.
I realize during recent programming projects that there are often little things that can be outsourced in order to help a developer deal with business logic more and technical issues less.
For example, a program crashes and you cannot figure out where it crashes. These kinds of tasks would be served well by somebody offshore. You only have to give them the program and ask them to find out why it crashes. They don't have to understand the business logic, only how to debug that language.
Another time we needed some test data. The developer could create a sample pattern and then offshore the data entry of similar entries.
Thus, a horizontal division of labor may be more effective than a verticle division.
[*] So will the alternative. I think the US does not offer anything economically special anymore, and we will become an also-ran economy. "Innovation" does not help much because much of the actual development of ideas can also be offshored these days. Thus, the source of innovation no longer generates as many local jobs as it used to. For every good idea there may be say 200 people bringing it to fruit. Now maybe only 50 of these remain local, for example.
Table-ized A.I.
Why should we let the cycle complete? And wasn't the East India Company British as opposed to American?
SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
Is not about providing better cheaper IT security services. It is about shifting liability.
People who bite the hand that feeds them usually lick the boot that kicks them
IS that many companies fail to actually do a real cost analysis on it. They buy in to the base cost figure of the outsourcing, and forget to account for any additonal costs. Then it ends up costing more and giving worse results, as well as putting people out of jobs.
Outsourcing is fine when it actually saves money and gets better service. I know many small companies that outsource their tech support. They can't afford to keep a fulltime tech guy since they have too few computers. So they have a local tech firm do their support. They get better support, since the firm has multiple people available, and it saves money since they don't have to pay someone full time/
However I also know plenty of cases where outsourcing has been a horrible failure. Like a company who I won't name that outsourced almost all their development to India and laid off most of their US staff. Well it turns out that the code sweatshop DIDN'T have tons of brilliant programmers willing to work for shit wages, they had tons of code monkeys who knew very little about programming. The code they got was unusable, they had to bring in contractors to try and fix it, and the result was a disaster. The cost of the outsorcing alone was more than inhouse development would have been (mysteriously, the figures grew from the inital quoted number as development lagged) never mind the cost of fixing it locally and that the final product sucked.
All I'm saying is it needs to be carefully evaluated. Way too many companies make shortsighted decisions because the inital number quoted from an outsourcing firm is slower. They then pay no mind to the other problems that might happen, and it ends up costing more and being worse.
The same company that makes it nearly impossible for an employee to enter the office supply closet to get much needed toner cartridge will outsource their intrusion detection, email and firewall systems without a blink.
"Why are you getting pencils, Dave? You already took two last week."
Table-ized A.I.
Keep in mind, outsourced security firms aren't domestically regulated like banks or other groups. If you can't "sue", "arrest" or otherwise influence the people watching you, then why give them the keys?
Outsourcing security seems like a good paradigm at first, but trust is earned. Here, we have serious certifications (clearances, CISSP, credit ratings, background checks, bonding, etc.) and there's a definite degree of employer influence over their employees.
Maybe its just me, but whenever someone I don't know says, "Trust me! C'mon, take a chance, live a little, all the cool CEOs are doing it" I'd conclude right away that these guys are going to ruin me. Mostly because, up until now, "TRUST ME" hasn't been too much of a necessity in outsourcing.
Anyway, outsourcing security could be one of the next "Great" phishing scams, after all -- why go for the salad when someone can go for the five course meal.
Your bank will answer ... something sybilline
"sybilline" ?!? A big word to use on /. sure, but perhaps you really meant "sibylline"? Spelling it the way you did is asinine ;)
Losers.. for the nth time understand the difference between outsource and off-shore..
Where the fuck was all this anti-offshoring movement when nike / reebok was selling you cheaper shoes (made in india/china), most of your apparel is made by the asian-tigers and a third world country like bangladesh. Now that you are losing your jobs (in the IT industry) you think it's not fair??? where were you when the others were losing their jobs???
First elect a president who is more concerned for america rather than unsuccessfully being world-police. Maybe things will change for you in due time.
and once again (n+1).. Outsourcing is not equal to off-shoring
What we really need to have are results of outsourcing. Sure, we've heard of Dell and a few other companies pulling work back to the US, but I doubt we'll ever hear of the failures or, for that matter, how bad it failed in terms of money and effort. I find it amazing that no investigative work has been done on reporting about the real effectiveness of outsourcing. My friend works for an IT recruiting company and they were told that Chase and another bank were quietly restaffing their US workers after moving most of their work overseas. The recruitment is for 4,000 workers for Chase alone. After the effort, move, and training, it turns out that they were getting the work at the same price, but now the quality sucked and were getting complaints from customers.
exactly...the current disparity in global standard of living will find a way of dissolving ..it cannot be sustained not in a connected world.
yes east india company was british but its the same business wisdowm that runs through all the comapnies wether american or british or even japanese.
Umm... most MSSP's are not located "offshore". Most of the people in that space are right here in the US. You've probably heard of them - Symantec, Internet Security Systems, Verisign?
Data regulations in Europe would probably entirely prohibit any European companies from even contracting with an overseas firm, certainly (sensitive data often cannot cross national borders, by law). I don't know of any specific US regulations, but I'd imagine the companies themselves are highly unlikely to go for this.
It's a strange world -- let's keep it that way
Maybe what should have been said.
"they will realize that the workers [of India] are customers of the[ir products and services] and [with the US] jobs [shipped to their country] people [will] buy much [and the US CEO's will drink merrily]."
I think many firms think outsourcing security is safer as they see their employees as their worst risk. I've watched managers knowingly do horrible things to employees...then they become paranoid that they employees with act in retribution.
To a large extent, employees are a worse threat since they will learn the company's weaknesses. The growing distrust between management and workers is scary.
Anyway, my experience is that managers who perceive themselves in a different class than workers don't like delegating secutity to members of the class they disparage.
Just finished Mitnick's "The Art of Deception". It gives me mixed feelings about outsourcing security. 1. Security should never be outsourced offshore, 'cuz offshore entitites are really beyond reach of our law. 2. Outsourced (onshore) security may be a good thing since the staff may be more immune to social pressure.
--- Attorneys Assisting Citizen-Soldiers & Families -
We outsorced our network management to the bozo that was our service provider. Without loss of generality, let's refer to him as Bozo.
I argued for a long time that we needed a firewall. Bozo argued that they were useless. A couple of years later, Bozo seems to have decided that firewalls were usefull and so decided that we needed a firewall.
Bozo then oursourced our firewall management to one of the better known computer security firms. At the time, I figured that was far better than letting Bozo handle it. I spent two hours on the telephone with someone from the security management firm identifying precisely what traffic should be permitted to and from each host.
But Bozo had them ignore all that and had them configure the firewall to his specification.
We ended up with a firewall that permitted just about everything either direction. The only exception was that it prohibited incoming traffic from spoofing local IP addresses.
One of Bozo's employees, let's call him Bozo Jr, came by to install it. He hooked it up backwards. The trusted side was hooked up to the Cisco router. The untrusted side was hooked up to our LAN. He then headed for the door without testing it. It was, after all, quitting time.
I stopped Bozo Jr before he left and made him wait while I tested it. Sure enough, it didn't work. So he unhooked the firewall and left. Neither Bozo nor Bozo Jr ever did hook it up. It was obvious what the problem was just from a quick look at the setup, but I was prohibited from reconfiguring their equipment.
I was completely amazed to find out that Bozo Jr considered Microsoft Windows of any flavor to be the most secure operating systems in the world.
When we finally got rid of Bozo. I was finally able to install a real firewall and we haven't had any problems since.
Given you can acquire the data secretly, you could easily hand it off to a third party who does some options speculation. People commonly bet with derivatives, especially day trader types. The right information about a company could make you a few million. If you are smart enough you can stay off the SEC's radar, an individual making $500,000 on some options will not ruffle any feather. Anyway the SEC has to know the data has been leaked for it to even enter their radar screens. Most companies would cover up the leak.
I work for a large company (about 2500 employees in IT alone). Our policy is to do very little outsourcing. We only out source the types of tasks that are well defined, most of it in legacy support. Out sourcing works very well in these situations. Any new development is kept in house where it can be better managed, and changes can be made faster when requirements change.
Out sourcing has it's place, but it should only be used in certain situations.
See my Home Theater
His policies made sense then and they do now.
I would like to hear the explanation of this statement.
I feel great. Now I can bitch on Slashdot all day and masterbate to Ballmer.
... I did an outsourcing gig earlier this year. I was flogging my resume trying to find work when this recruiter called me and asked me to do a weekend job doing an upgrade rollout at a major bank.
I was told to show up on Friday afternoon and that I'd be working with a group pretty much all weekend. No one took a look at my ID, or had me sign anything. They believed me that I was eligible to work in the US even though most of my resume was working outside of the states. Asking around I found that this was the case with most of the forty odd nerds they had rounded up for the job.
We were all working for a subcontractor of a subcontractor of a major IT firm from Texas. We were all given pretty much free reign of the executive offices and all shared the same username and password. There was basically no supervision what so ever.
It would have been so easy to install a good deal of malicious software... heck, it wouldn't have been that hard to swap out the master image to take over pretty much every machine on the network.
I don't even want to think of what goes on in third world countries. That weekend really made me second guess what goes on in the US. If the bank had it's own IT staff, seven people who could work together could have done the same job that it took about sixty including supervisors and honchos and I am sure the cost of their salaries for a year was less than was wasted on that crew. The upside was they did buy us good pizza!!!
I have to give them the whole development system and the robotics that it runs including access to my CVS tree.
Bad analogy, dude
So why are you here? Just to trash people?
/.
If you don't like slash dot then don't bother us with your slanted stereotype of us that isn't based in reality.
Anyone can post here, so any point of view is possible here. If you don't know that then you should just stay away from
Dont you think the people in India, China and Pakistan are concerned about sercurity as well? I mean think about it. If there is a continuous lapse in secrurity and you they caught, they go out of buisness. The fact is that to stay in business these offshore companies need to ( and some do) realize that we might loose buisness if we let all this personal information be readily available for our employees to view and share.
"The only downside to the book is its $85.00 price, "
:P
Ever since my job was outsourced, I can't afford books. Or food, or beer...
I'm actually making more money since I get OT while at a client's facility but I'm liking my work less. It doesn't look like things will be changing any time soon.... the US corporate world at its best!
How is it possibly that anyone in those companies care about security in the first place? They use shitty application software, written by undereducated hacks (both American and foreign ones), on unpatched Windows boxes, run by poorly paid people with barely enough qualifications to run their own desktops. No outsourcing can make this situation any noticeably worse.
Contrary to the popular belief, there indeed is no God.
I cringe when I hear CEOs say "IT is not a core competency" of their company. I want to smack them with a cluebat and yell:
"When the crew you outsourced your IT to screws up, how long will your company stay in business? If the answer is 'Not long', then you'd better MAKE IT A CORE COMPETENCY!"
The problem is that far too many people in executive management have no common sense whatsoever, and writing new laws won't change that. I don't know what will, other than easing up on the red tape that holds back the small businesses that by rights ought to wipe out many of the big and stupid ones.
IT is such a huge force multiplier when it's done correctly that it's monumentally stupid for any business of significant size to take risks with outsourcing.
Also, have the execs read "The Goal" by Eliyahu M. Goldratt. Most of it is common sense to anyone with good problem-solving instincts but I still picked up a few things from it.
Who'd a thunk it?
very frustrating forking over your Social Security Number to someone in India who makes $1.50 an hour.
SBC DSL supprt is in India. Good luck if you have line problems with your DSL..they won't be able to help.
Dell support is in India.
Transunion (Credit Reporting Bureau) support is in India --this is like the worse thing you could have overseas..everyone's..and I mean everyone's financial information, at the fingertips of someone who could quite possibly sell if for more than they make in a year in India. No wonder ID theft is so rampant these days.
We need some sort of legislation that details specific things that absolutely cannot be shipped overseas. Medical data and financial data certainly should be part of that.
Normally SWIFT keys are looked after by procedures and also legislation. Whether a company in a developing country can do either is arguable, even if the company is a wholely owned subsidiary.
What about the second wealthiest person in America? What about the members of Responsible Wealth? What about Gordon Moore, who in addition to founding Intel, has been giving away huge sums of money for decades? What about these 50 philanthropists?
As for politicians, having worked in Washington, D.C., I can tell you that the vast majority of the elected and appointed people I met had very little interest in padding their fortunes. Politics is in general a much more difficult means of obtaining wealth than going into business. Sure, there are people who rotate between business and politics, taking advantage of the linkage. But there are plenty of hardworking politicians at the state and national level who really do want to do some good. You may not agree with their political leanings, their methods, or their effectiveness, but to paint them all as greedy bastards, while satisfying, is quite an exaggeration.
Read the EFF's Fair Use FAQ
My former employer did exactly this; they fired a highly skilled team of info security personnel (no advance notice by the way, because then they might have done something vindictive, right?) and outsourced security to a small local company who in turn relied heavily on labor from India. Not only that, but we're talking about the kind of infrastructure company that would be the first to go if anyone attacked the US with any sort of serious effort: one of the four major railroads. This was the product of a megalomaniac technology VP who wanted to save money to tyhe point of removing on-call cell phones, because the cost savings were worth the additional downtime while support personnel looks for a pay phone. The company was on the Forbes top 100 companies to work for in 2000, but so was Enron.
Did I mention this was my former employer? Good.
OK, </rant>
#o#
O Moo.
I am saddened by most of the posts on this topic, most of them being downright vindictive and more dangerously, ignorant.
:)
I am an Indian, in Hyderabad, who works for one of India's IT giants. Our business model is definitely one of outsourcing and we've been enjoying record profits for the last ten years (except a slight hiccup during the dot com bust)
Trashing companies such as the one I work in may be the political flavour of the month, but I do ask you all to at least think of some of the benefits.
For most of you, security and the quality of work done seems to be the two major bones of contention. I agree there are a lot of shady companies out here who do not follow rules or regulations but do you think companies like Wipro, Infosys (I can only name the Indian ones) are a shoddy bunch? There is definite value to be had here. At least ponder on what your CEO thinks and the value add to your company.
I have had to travel a lot these last few years, going from one client site to another and its really helped me understand different cultures and thought processes.
For all those of you who mock outsourcing or are scared of losing jobs, come on, come to india with your resume. Companies here will grab you up, you can have the time of your life and you can even visit the Taj mahal
i know this post wont change anything. It is more an emotive issue than anything.
Oh well.
I see panicked morons crying foul when their jobs are hacked by *better*,cheaper,more dependable and consistent guys elsewhere in the world. I heard the same cry when Reebok and Ford shifted there factories South America and Asia where *better* worker force are available for more compatable price. Realize the fact. People always look the *better* ones.Face it;the coders in India and China are better than who you find here in Seattle or San Fransisco.Now try to outplay them.Losers, you cry out...or write a book like this.
This book is merely trying to capture mindshare by linking security with the current buzzword of outsourcing.
Most critical security issues start at home - remember the two Bell Labs engineers who pushed out Packetstar code a couple of years ago? Or the famous Cadence lawsuit against another former employee who founded a rival company (the name escapes me at the moment).
I have a very sneaky suspicion that a major US student loan company outsources their customer support department. Why worry about this? Do you care that your sensitive information is being accessible halfway around the world? How many of us still have student loans to pay off?
Linux at home
not pissing off any of your employees who are gun nuts.