Managed Services and Security Assessment
Managed services and security assessments monitor systems, identify vulnerabilities, validate protections, and deliver expert oversight to ensure resilience against evolving threats.
4 slides · 3 min read · Domain 6
Managed services is loosely defined as having a third party take on responsibility for many if not all aspects of performing a set of functions for an organization. The service provider has broad responsibility to identify and anticipate needs, select and apply methods and practices, conduct those activities, assess their effectiveness, and keep the customer's management fully informed of progress and issues that arise. From call centers to network and security operations, managed services providers are making it possible for many businesses to dynamically respond to changing business conditions without needing to invest upfront in capital equipment, systems, facilities, people, or readiness activities. In many respects, managed services provide cloudlike scalability for people-powered activities.
Ideally, a security professional's organization uses managed services under a contract and service level agreement (SLA), which establish a full and cooperative relationship with a provider.
This would provide appropriate visibility into the various security compliance audits and formal assessments that the provider has undergone. It might also provide a collaborative environment in which your own development and deployment teams can share in the in-depth security know-how that your provider has at their fingertips.
This SLA would also provide the contractual and technical
Security professionals will need to be means by which your security involved with managed services providers on testing and assessment two fronts:
activities, including audits, of
- Those who deliver IT or information
your systems and applications services, particularly in the areas of can benefit from the providers' security, identity management, incident response, and business continuity (BC) collaboration.
and disaster recovery (DR) services.
- Those who deal in other services but whose personnel and information systems have some form of shared access to, or use of, the contracting organization's assets, facilities, people, and information.
Many organizations initially opt to engage a managed services provider on a pay-asyou-go basis. That relationship will evolve with growing needs. Budgetary realities often shape both consumer choices and a company's approach to knowledge management and internal development.
Even for slim budgets, the SLAs you have in place with your cloud and managed services providers should grant you summary-level security audit report information.
From this, you may determine how much trust and confidence you can have in those services and their providers, and how much your organization must take on its own shoulders.
Increasingly, organizations must evaluate the security controls of their vendors' supply chains to properly assess risk. This is especially important, as the use of third parties to provide systems previously managed under the primary organization's control umbrella continues to rise. Breakdowns in security practices may have devastating consequences for all participants in the value chain.
Not surprisingly, most organizations also exist within some other organizations' supply chains. The principles of supply chain management must be applied to both upstream (supplier) and downstream (customer) relationships.
Several well-established standards address supply chain risk management. The ISO 28000 series of standards addresses the development and application of a supply chain security management system.
