Take Long Security Look Before Outsourcing Leap

Michael Vizard
Slide Show

Top 10 Security Questions to Ask Before Outsourcing Any IT

When it comes to cloud computing specifically and outsourcing in general, there are obviously a lot of concerns about security.


But by and large, the security expertise of IT services providers tends to be greater than that of the internal IT department, so chances are good that security might be better handled by them. Of course, they have to offer to actually manage your security. For instance, Amazon pretty much tells customers that they are on their own when it comes to managing the security of the application workloads running on its clouds.


But before you decide to outsource your IT operations, Rob White, director of IT security services for Fujitsu, says there are 10 questions you should be asking about security. The goal, says White, is not to come up with an argument against outsourcing, but to create a scenario where the cost of security for the outsourced environment is actually less than it would have been to run it in-house.


White says that in the bad old recent days, the best most customers could expect from outsourcing was "their mess for less." In other words, the service provider would essentially replicate their internal security systems either on a hosting service or manage it remotely at less cost.


But today customers can demand operational excellence. In the case of Fujitsu, that comes in the form of managed security services for both on-premise and hosted cloud computing environments built mostly around security software from Check Point. While Fujitsu will deliver security services around any security software a customer wants, White says Fujitsu prefers Check Point because it's the only security vendor that offers a complete security portfolio from the data center to the end point. As White notes, if you really want to reduce the cost of security, one of the best places to start is by reducing the number of vendors involved.


So while customers can still get their mess for less, White says the new goal should really be to get industry best practices for less than it costs to manage your own current mess.


That might seem like a radical idea. But given the overwhelming interest in reducing the cost of IT these days, it's little wonder that there is a phenomenal amount of interest in lowering the cost of security. After all, it's difficult to prove that there is a return on security investment, so from the perspective of the business, security is a cost of doing business. And like all costs it needs to not only be managed down, but the quality of the service needs to improve as well.



Add Comment      Leave a comment on this blog post
Sep 21, 2010 11:56 AM Shaleen Shah Shaleen Shah  says:

As the adage goes..." you get what you pay for.."  and many business startups or small business owners make the huge mistake of trying to cut down cost on things that matters most, like data security and quality workers.  Then, after they've been had they'll post their rants on the Web with a major headline:  Ripoff.  This could have been avoided in the first place if you gave your business a bit more value for money.  It's important to also consider your Intellectual Property Rights when you outsource to vendors:  http://blog.ajeva.com/2010/06/client-101-protecting-your-intellectual-property-rights/

Reply
Nov 4, 2010 3:07 AM Chad Black Chad Black  says:

Safety measures are not generally taken into consideration. This is an integral part of the system but there should also be a way to lower security costs efficiently while delivering high quality services as well.

Reply
Sep 18, 2013 1:18 AM Dryle Tatum Dryle Tatum  says:
Honestly yes, business security first before anything else. Reply

Post a comment

 

 

 

 


(Maximum characters: 1200). You have 1200 characters left.

 

null
null

 

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.