Outsourced security called battle tested - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Software

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Twing targets communities with new search engine. Listen now!

Network World Panorama

Ken Russell on making applets fast. Listen now!

JavaWorld's Java Technology Insider

Additional Resources

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Learn how to Create a More Efficient Virtualized Data Center Novell

Find out how you can consolidate Windows workloads and create a more efficient virtualized data center in this informative webcast, "Reduce Complexity and Cost - Windows Server Consolidation with Virtualization." Six concise webcast modules are available for your viewing. Watch them all consecutively or only the topics that interest you. The modules cover performance, user case studies, enterprise-level support, managing windows workloads, setup and configuration and the future of virtualization. Learn more today. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

Juniper has this in WX/WXC, BlueCoat now has this (acquired with the Packeteer acquisition.) Both companies...- Anonymous

Join the Discussion

Partner Content
CA logo

CA Network & Voice Resource Center

Comprehensive Network & Voice Management Visit CA Network & Voice Management Resource Center and get insights into industry best practices, information that helps you to address your challenges.

CA Network & Voice Management Resource Center

whitepaper

Managing Voice Over IP for Successful Convergence

Voice over IP (VoIP) has much to offer in cost savings but some customers have concerns about VoIP call quality compared to the quality of traditional voice services. This white paper will help you learn how to take the right steps so that voice quality is assured.

Managing VoIP for Successful Convergence

whitepaper

The Changing Face of Network Management

Managing your network is serious business. This paper discusses the benefits of integrating configuration change-awareness into your network fault management solution

Download Whitepaper

Outsourced security called battle tested

By Ellen Messmer , Network World , 06/13/2005
  • Social Web 
  • Email 
  • Feedback 
  • Close

WASHINGTON, D.C. - Outsourcing corporate security is no longer risky business and large organizations should hand off network monitoring and security services as soon as possible.

That was the main conclusion Gartner analysts presented to about 2,000 IT executives at the firm's IT Security Summit last week. Gartner predicts the future of security is in the cloud and expects to see more services such as MCI's WAN Defense, announced two weeks ago.

"Why should I filter out this garbage at my end? Outsource as much of the day-to-day busywork as you can, as soon as you can," said Gartner analyst John Pescatore in his presentation titled "The Near Future of Network Security."

Pescatore acknowledged this is a radical change from what Gartner would have advocated in years past, when it viewed security outsourcing - which requires a company to entrust an outsider with critical support - as controversial.

"It's just not controversial anymore," Pescatore said. He said the level of expertise exhibited by the first-generation of managed security service providers (MSSPs) along with the rise of carrier-class high-speed security gear from vendors such as iPolicy Networks indicate that security outsourcing can evolve into a trusted service. Customers need not purchase their own customer premises equipment (CPE), Pescatore says, particularly for perimeter defense.

Managed security services will evolve into "in-the-cloud services" in which network traffic is cleaned of spam, viruses, attack traffic and other problems before it reaches the enterprise, and perimeter firewalls and IDS reside with the carrier, said Kelly Kavanaugh, whose presentation was titled "Security in the Cloud: Take My Security Hardware, Please."

Traditional pure-play MSSPs such as Symantec, Internet Security Systems and Counterpane Internet Security, as well as the larger IT outsourcers such as EDS and IBM, are most often associated with remote monitoring customer IDS, firewalls and other gear.

But he predicted, "It becomes a utility that's shared. For enterprises, it's a way to let go of having customer premises equipment."

He said a number of in-the-cloud anti-spam and anti-virus filtering services already exist, including those from MessageLabs and Symantec's Brightmail outfit. While MSSPs also might offer their own version of in- the-cloud security, Kavanaugh explained that "the carriers have the best opportunity to deliver in the cloud" because theyprovide the essential connection closest to the customer's network.

A mixed reaction

The security-cloud concept generated a mixed reaction among attendees.

"I couldn't see doing that at this point," said Peter Walker, chief security officer at healthcare insurance provider Blue-Shield of California. The company relies on Counterpane for monitoring firewall and intrusion-detection and prevention gear, but he said he would be reluctant to forgo owning his own security gear.

Walker said his close relationship with Counterpane gave him confidence in outsourcing equipment monitoring and its cost-effectiveness. But he couldn't envision not owning a security CPE.

Phil Maier, vice president of information security technologies at Inovant, a division of Visa that provides IT support, said he also had reservations.

"I'm a security-paranoid, I trust nobody," said Maier, adding his views about outsourcing had been influenced by his past experience working for a defense contractor where strict military guidelines ruled.

"But sharing your infrastructure with another organization is something that can happen and it can work," Maier added, noting that outsourcing of security was the direction is which Visa was headed since doing so would eliminate the need to hire more staff to monitor security devices.

Click to see:

Not so fast
According to Gartner, outsourcing corporate security is no longer risky business, but there are some issues.
Pros
Requires less staff for round-the-clock equipment monitoring.
Removes the need to purchase customer-premises equipment.
Reduces equipment support cost.
Cons
Potentially limits security gear support.
Introduces legal questions, especially when outsourcing in a foreign country.
Leaves users wary of long-term contracts with some managed services companies.

But larger organizations say they're seriously examining the possibility of adopting security outsourcing.

"We intend to transfer assets under an outsourcing contract," said Byrne Huntley, director of the IT services center at the U.S. Department of Health and Human Services. HHS is in the middle of a bid process in which the goal is to obtain a significant portion of its network equipment and security as a service in which the supplying vendor would own and manage all the assets under a five-year contract.

1 | 2 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code