thecybersecurityreview

JAN - MARCH - 2021CYBERSECURITY REVIEW 19 Andy Chauhanand safety practices maybe part of the fabric of an organisation, however to embed them in a partner organisation requires changing unconscious behaviour in the partner staff which cannot be underestimated. To harness true value, the outsourcer and the partner need to have a synergy which sees them operating as one, both from a culture and value perspective. 4. Service Definition, Integration, and MeasurementMost services are rarely standalone, they need to operate in an ecosystem which could be operated by multiple service providers (either internal or external). To ensure delivery of a consistent and effective business service requires the underlying service level objectives (SLOs), service level agreements (SLAs), and key performance indicators (KPIs) of all the supporting services to be aligned. Anything that cannot be easily defined, chances are it cannot be measured and cannot be delivered to expectations. A key aspect of measuring a service requires focus on leading and lagging quantitative metrics (such as response times, availability of services) as well as qualitative metrics (% of certificates with no service owners). 5. Cybersecurity ConsiderationsCybersecurity functions are not any different to IT functions that are being outsourced and as such they are faced with the below options, each with their trade-offs. Below are some considerations ­· Completely outsourced ­ this model is suited for highly commoditised activities that are static and easily measurable, examples would include help desk /Level 1 support or monitoring of services (eyes on glass). These can include some infrastructure services such as email, internet, elements of network security.· Hybrid ­ this model is suited to services that have a commoditised component but also a large business engagement and continuous change component. Identity &access services that have continued onboarding or significant business engagement such as data protection, segregation of duties would fall in this category. · Insourced ­ this model is suited for services going through a high degree of change, with substantial number of internal service integration points and significant business involvement. This model is also suited for services that are nebulous, hard to define, measure and once engaged, hard to disengage.So far, most of the above considerations have been focussed on managed services, however, there are cyberspace governance services that are particularly relevant in providing assurance over managed services. These services particularly, security architecture and design, security reviews, penetration testing, supplier security assessments in conjunction with the service ownership function are essential to derive value from an outsourced arrangement.In summary, a successful outsourcing arrangement either for IT services, business or cybersecurity services requires a good understanding of your own business outcomes, what is on offer and the value-cost-risk trade-offs that you are comfortable embracing. A successful outsourcing arrangement either for IT services, business or cybersecurity services requires a good understanding of your own business outcomes
< Page 9 | Page 11 >