Third-Party Provided Security Services
As mentioned throughout the course, organizations can avail themselves of services offered by external entities to enhance security. This is especially true for organizations for which security is not a core competency.
12 slides · 5 min read · Domain 7
For instance, an agricultural retail business might not have the expertise and tools to create a comprehensive and thorough security program; the core competency of that business is to sell agricultural goods, not to secure data.
There are a variety of security services currently offered by professional providers, including the following:
Threat intelligence
The provider may perform open-source monitoring or conduct their own investigative efforts to determine what threats pose a risk to their clientele. This can include general threats to clients in a certain region or industry, or using certain products, or it can include threats against specific clients based on their operations or personnel.
Network monitoring
Because detecting network attacks can require a significant degree of analysis and expertise, not all organizations are in the position to monitor their own environment. Network monitoring as a managed service can be performed remotely from the provider's location, or onsite at the client's facility.
Physical security
Many organizations hire guard services from an external provider as opposed to bringing on guards as employees. This obviates the additional personnel burden (benefits, administrative costs, etc.), costs associated with training and managing those personnel, and with creating and running a program that might not be a core competency of the organization.
Network management
While not strictly a security service, managed network providers are often tasked with many of the security functions associated with IT administration such as enforcing network usage policy, monitoring, patch management, asset inventory, and so forth. Modern managed network services include cloud computing hosting.
Audit
Again, not strictly a security service, external audits can address security needs such as verification and validation, vulnerability scanning, certification of compliance, configuration maintenance, and the like.
When contracting with third-party services of any kind, it is important to perform due diligence in the form of research about the provider's ability to perform the requisite tasks and maintain the necessary level of customer satisfaction and protection of assets.
This is even more essential when the services in question involve security that requires the client place a great deal of trust in the provider. This often entails (but is not limited to) the following measures:
Review of governance
The client should review the provider's approach to service provision, including security policy and procedures.
Service-level
Non-disclosure agreements (SLAs) agreements (NDAs)
The client and provider must agree, explicitly, what constitutes full and accurate satisfaction of the terms of service.
The provider must agree to protect and limit dissemination of any of the customer's data that the provider may access during provision of the service. This also includes the provider agreeing not to take any action beneficial to the provider based on the customer's information (such as using that information for personal financial gain).
Insurance / bonding
Professional service providers are necessarily in a position to cause significant negative impact to the customer and should obviate that risk to build trust in the relationship. One technique for accomplishing this is to provide financial assurance that the customer will receive restitution for any damages resulting from the provider's negligence/failures. Common methods include a form of risk transference, such as a surety bond or errors and omissions insurance policies.
Audit / testing The provider should allow the customer to perform surveys reviews of the provider's operation and the service itself; these can take the form of onsite audits, performance monitoring, penetration testing, etc.
Strong contract language
All terms of the managed service must be enforceable and legitimate for all jurisdictions and applicable laws where the service will be rendered. This should involve exhaustive review by legal counsel for both parties.
Regulatory approval
As in all matters involving compliance requirements, any regulators that oversee the organization need to be informed and grant acceptance of any managed service that might affect compliance.
Contracting for services in the public sector is significantly different than contracting in the private sector. The procurement regulations are complex and are often designed to serve other governmental goals besides obtaining the best service at the lowest cost.
This may include preferences for certain groups or businesses, limitations due to political constraints (embargos, international agreements) or encouraging the development of local industries over those located outside the jurisdiction. Further, the procurement activities are intended to provide a high degree of accountability for the proper expenditure of public funds.
In the EU, the public procurement policies establish minimum procurement practices for the EU members but are extensively augmented to meet national requirements. In Canada, the government contracting regulations are augmented by the Standard Acquisition Clauses and Conditions (SACC) manual, and further influenced by other legislation, precedents of common law and the requirements of international trade agreements. In the U.S., the several thousand pages of the Federal Acquisition Regulation (FAR) provide an equally complex environment for the acquisition of goods and services. The FAR is not directly applicable to the procurement activities of the states and sub-jurisdictions, each of which have their own contracting rules!
In short, government contracting activities are exceedingly complex, and the consequences for failing to follow the regulatory requirements can be severe.
Security professionals involved in acquisition activities either as contractors to, or employees of, governmental organizations need to clearly understand their role in the acquisition process and the scope of their authority to ensure the contracting activities comply with statute and regulations.
