Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


January 17, 2008

5 Tips for Buying Managed Security Services

Including 5 must-have managed services for SMBs
RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

 Executive Summary:
Five essential tips can help SMBs determine whether and how to add managed services to their IT portfolios. Also, learn which five managed security services provide the greatest value for the majority of SMBs and which services might not make the best sense for small businesses.

Managed security services have never been more popular, especially among small-to-midsized businesses (SMBs). Many SMBs faced with Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley (GLB) Act, or Sarbanes-Oxley (SOX) Act compliance have turned to outsourced security services. But managed security services can be difficult to implement if you're not adequately informed or prepared.

Here are five essential tips that can help SMBs determine whether and how to add managed services to their IT portfolios. I tell you about five managed security services that provide the greatest value for the majority of SMBs and identify a couple services that might not make the best sense for the typical SMB. I also give you specific questions about each service to ask potential service providers.

Tip 1: Choose the Right Managed Security Services
Choosing services that line up with your stated business objectives and available resources is key. For example, yours might be a small company with a limited IT staff facing HIPAA, GLB, SOX, or other compliance requirements. In this situation, you might be better off outsourcing the compliance scans than trying to buy the equipment and hire the staff to perform the scans yourself.

I've identified five managed security services that might make the most sense for the majority of SMBs and two that might not be such a good idea. Keep in mind that while certain services might be a great fit for a midsized-to-large firm, they might not be applicable or useful for the SMB.

Malware protection. Viruses and spyware have the potential to affect almost every computer, especially those connected to the Internet. Most SMBs have some form of anti-malware application installed. Yet, many SMBs still wrestle with viruses and have a difficult time keeping virus software updated and, worse yet, eradicating infections within their networks. Managed malware protection ensures that your anti-malware software from Symantec, McAfee, or other vendor is always up-to-date.

Some practical questions to ask potential service providers include: How often do you update your software, and do you update virus definitions automatically? How often are systems scanned? Might those scans affect my company's unique applications? Compatibility testing might be necessary.

You should also ask what happens if you do get a virus. Does the provider notify you, and will it eradicate the malware for you? What happens if the provider can't remove the virus? In some cases, you might have to rebuild systems yourself if the service provider can't resolve the problem, although some providers might offer to do this for you. You should take a careful look at how the service fits with your recovery plans.

Spam protection. Spam can be overwhelming, especially to the SMB. Many network appliances are available to mitigate the effects of spam but often require constant tuning and management. Outsourcing spam protection to a service provider can be a valuable exercise. For example, Google's Postini offers a completely offsite solution with no hardware footprint. All your email is routed through its servers and processed before being delivered to your email server.

Some things to keep in mind when looking at outsourcing spam control are: How much control will you have over the email filtering process? Will you be able to enact a policy change fairly quickly?

False positives (i.e., emails that are legit but are flagged as spam) are a concern with antispam solutions. Antispam software and service providers aren't likely to provide you good data on their false positive rates. And even if they did provide data, each company's users have different mail patterns and characteristics, so a provider's average false-positive rates might not hold true for your company anyway. Thus, you might ask a service provider if it can set up a test during which your incoming email continues to be sent to your normal email server while also being copied to a second stream that flows through the service; such a test will let you review the service's performance before cutting over to it.

Whether a provider can perform such a test or not, find out what kind of reporting is available to you. You'll want to see what types of emails are being flagged as junk to help minimize false positives yet maximize junk mail identification as the company continues to tune the service for you. You might also want a service that lets users review their individual junk mail for false positives and customize their own white lists and/or black lists.

The service provider will be processing all your email, so you might want to ask about its availability record and what happens if the service does go down. Also, you might want to know about the measures the provider has in place to secure your data and what the company does with it once it's been processed for spam.

OS patch management. The ubiquity of Microsoft OSs has created a target for those that wish to exploit software vulnerabilities for maximum effect. Staying up-to-date on Microsoft patches and the vulnerability status of systems across your network can be challenging. Managed patch deployment services such as those offered by Lumension Security's PatchLink remotely install patches for you and identify unpatched systems.

Important questions to ask include: How are patches deployed? Is the deployment automatic? Is it seamless and hidden from the users, or do they have to perform some action (e.g., click Yes)? What sort of testing can or should be done on my systems to ensure compatibility before a patch is rolled out? What happens if a patch breaks my system? What’s the rollback process? How do you handle reboots—can they be scheduled or are they automatic?

Remote backup and disaster recovery. If you work in a doctor’s office or legal firm, you have lots of sensitive and critical data that you need to have long-term access to. Managed offsite storage services provide an effective means to automatically back up critical data to secure remote locations. This allows you access to that data during a disaster scenario (large or small).

Some important questions for the provider to answer are: How secure is my data? Is it stored on servers in racks and cages separate from other companies' data? Is it backed up from your site? How easy is it to retrieve my data during a recovery—can I restore it remotely, do I have to call someone to get approval? What are the recovery times? Are they guaranteed? Are you involved in the restoration, or are you nothing more than a remote repository? What sort of reporting mechanism is available to see how my backups are progressing? Can I test the backup and recovery processes?

Compliance scans. Many security service providers offer compliance scans that can be one-time or recurring events in which your network is scanned for vulnerabilities. This activity can help you comply with HIPAA or GLB requirements. What is most important about these scans is what you plan to do about the vulnerabilities detected. Can the provider help you mitigate the risks identified? Hopefully, yes.

Although many managed security services are available these days, not all make sense for the typical SMB. A discerning SMB should select only those services that are consistent with its business goals and IT objectives. A couple of services that might not be a good fit for many SMBs are firewall maintenance and monitoring, and intrusion detection system (IDS) or intrusion prevention system (IPS) log management. Every SMB should have a firewall to protect its Internet connections. However, as an SMB, your firewall is probably relatively unsophisticated and doesn't require much maintenance or monitoring, so you likely don't require a management service for it. IDS/IPS, particularly at the host level, adds a layer of complexity not appropriate for most small businesses. Without an IDS or IPS, you obviously have no need for a service that manages its log.

Tip 2: Choose the Right Provider
Make sure the security service provider knows your industry. If you have HIPAA compliance requirements, ensure the provider is HIPAA qualified. The same goes for GLB, SOX, and so on. Look at how focused the provider is on managed security services—is its solution just one of many products or is it integral to the provider's core business? What’s the provider's growth potential? Is it a forward-looking firm that stays on top of the trends?

Find out about the provider's security practices and what it will do to protect your data. One good question to ask is whether the company can show you a Statement on Auditing Standard 70 (SAS 70) report. An SAS 70 review conducted by an independent auditor shows that the provider has been found to have satisfactory controls and safeguards in place for handling its customers' data.

You'll want to make sure that working with the service and the provider is simple and efficient. Try to determine how difficult it is to implement the service and how much of your time it will take. Does the implementation involve a lot of downtime? What sort of rollback plan does the provider have if the service proves to be unworkable for you? Ask for references, and talk to a few current customers to see what their experience has been with the vendor. Check with the Better Business Bureau. Find out how the provider invoices—yearly, monthly? You don't want a paperwork nightmare. Finally, try to stick with just one or two providers for simplicity's sake.

Tip 3: Pay Attention to the Contract
The devil is always in the details, and the contract is your opportunity to flesh out all those details that could make the difference during a stressful security breach or restoration.

With an anti-malware service, it's important for the contract to stipulate how often the provider will update its software and perform system scans. The contract should also outline the provider's response plan in the event of a security breach such as a virus outbreak or a successful hacking attempt. Know what your role will be and whether the provider will have onsite support available if needed.

A spam protection service contract needs to spell out the message log storage size limit, quarantine storage size limit, number of users, and so on. That way, if you suddenly grow your business, you know you need to upgrade your service to accommodate the additional email.

The contract for a patching service should tell you when patches will be installed. You might wish to have a test phase of some sort before patches are deployed en masse; the contract should spell out how this will happen. The contract should also address how reboots will be handled. You might want to notify users before a reboot is necessary, or you might prefer automatic reboots. How will you be notified about folks who haven’t rebooted?

In the case of a backup and restore service, the contract should address the roles and responsibilities of both parties. It should spell out how quickly the provider will respond when you initiate a restore and what will happen if a restore doesn't work. Does the provider have an escalation path for you to follow? Also, does the vendor need your permission to perform certain tasks (such as a restore)? Make sure you get these details in writing, and make sure you know what the provider can't or won't do.

For a compliance service, the contract should specify how often a scan is performed (monthly? daily?) and what the provider will do when it identifies a vulnerability.

From an overall perspective, is the service level agreement (SLA) flexible for your specific needs or is it a canned contract that leaves you no ability to customize it to your requirements? Are all requirements (for both parties) clearly documented, and do you understand your own responsibilities? How easy is it to get out of the contract if you don’t like the provider's service? Are you locked in immediately, or is there a trial period? For example, if you pay a year in advance, do you get any of your money back if you quit the service?

Tip 4: Examine the Reports
Reporting is a crucial aspect of managed security services. Trusting someone else to handle aspects of your business is a big step. Ensuring that they're doing what they say they will is important, and robust reporting on a regular basis is necessary to ensure accountability. Can the provider show you what it's doing? How often do you get reports, and are they meaningful?

Tip 5: Do the Math
Before you sign a contract, be sure that a managed service makes monetary sense. Does the quoted price seem fair, and does it work for your budget? Does it compare favorably with what you'd pay to buy the equipment and hire someone to perform the task?

The responsibility and liability for securing your business can never be outsourced. When you contract for a managed security service, you're outsourcing certain tasks related to securing your organization, but you're still ultimately responsible for your organization's security. Managed security services are simply tools to assist in meeting that goal.

Managed security services’ popularity has never been higher. Yet implementing these services should never be done off the cuff. Careful consideration as to how a provider fits into your business plans is crucial. Use the tips outlined above to make an informed decision, and choose only those services that are consistent with your business strategy.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Accessing Database Data with ADO

...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...


Related Articles Patch Management Solutions

Backup and Recovery Basics

Antispam Solutions for Business

Keep Out: Spam and Viruses

Security Whitepapers Protecting (You and) Your Data with Exchange Server 2007

Extended Validation SSL Certificates

Unauthorized applications: Taking back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Increase Application Performance
Free White Paper by Editor's Best winner, Texas Memory Systems.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing