|
2010 Could Be The Year For Security Outsourcing, Forrester Says |
|
|
|
Source: Dark Reading - Posted by Anthony Pell
|
The new year could bring new relationships between the enterprise security department and the security outsourcing firms that want to serve it, according to a new industry report.
According to "Twelve Recommendations For Your 2010 Information Security Strategy," a report published yesterday by Forrester Research, enterprises may rethink the "outsourcing" concept, making it more of a "co-sourcing" approach.
"Some companies employ outsourcing vendors because they want to wipe their hands clean of regulatory compliance or hand over a messy environment in the hopes that the outsourcer will be able to fix it," the report observes. "Those are obviously the wrong reasons to outsource.
"First, even if you outsource security, you're still accountable for the protection of that data," Forrester says. "Second, if you have a messy environment, the outsourcer does not have any incentive to fix it -- and the nightmare of managing that environment will be worse if a third party gets involved."
Enterprises should be careful to perform due diligence on security outsourcing providers, and define ways to hold the outsourcer accountable, the report advises.
Read this full article at Dark Reading
Only registered users can write comments. Please login or register. Powered by AkoComment! |