Friday | 5 September, 2008
Computerworld
Outsourcing security tasks brings controversy
Outsourcing security gives in-house IT staff a chance to be freed up from mundane tasks, but not everyone likes it
Ellen Messmer (Network World) 25/03/2008 08:06:51

Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

When it comes to outsourcing security functions, skepticism still rules the day for many users. The idea of handing over control of network security to an outside firm paid to maintain gear, monitor for attacks, perform scans, collect logs or update security software for employees is, to say the least, controversial.

Security managers are split on the issue, arguing it's either a boon or bane for the company. According to advocates, outsourcing security gives in-house IT staff a chance to be freed up from mundane tasks to deal with more strategic matters without having to take on additional staff. The naysayers worry that outsourcing means losing sight of security risks because outsiders will mechanically follow a contract without thinking critically enough. Whether outsourcing is cost-effective is part of the debate, too, but the central question of control stirs the greater emotion.

Those bullish on security outsourcing say it's a way to move their in-house security specialists, already in short supply, into more strategic jobs while making sure everyday tasks get done.

"We either have to bring in more internal IT people or get other people through outsourcing security services," says Andre Gold, lead, IT risk management in the North American arm of ING, the Holland-based global financial services firm.

Gold says tasks such as patch and vulnerability management tasks or antivirus support are consuming a lot of staff time that might be better used in strategic risk-management operations for online business goals with partners and customers, for instance.

"I'd rather push the ING people up the ladder," Gold says, noting that next month ING expects to select at least one security outsourcing provider -- it may be offshore in India or elsewhere -- for large, multiyear contracts to handle a wide variety of data and network-security management remotely.

"I call it security right-sourcing," Gold says, adding that ING already outsources some IT maintenance and application development. Consequently, advocating security outsourcing was not a culture shock at the company. Gold says he expects security outsourcing to prove cost-effective over adding in-house staff, but he says in this case, it's not the primary motivator for doing it.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

EMC Data Profiling for File System and Exchange Server Environments

There has been an explosive and seemingly unmanageable growth of information in business today. Discover how EMC can utilise intelligent data analysis to develop a strategic plan for your business and optimise your organisation’s file system and Exchange Environments.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links