* Outsource the work but stay in control of the security responsibilities
endif; ?>Outsourcing is one of the hottest trends in business and I am constantly amazed at the variety of functions that are being outsourced. In addition to the outsourcing of traditional IT, HR, call center and accounting functions, I have recently read about offshoring legal work and outsourcing R&D. Is nothing sacred? I even learned recently about a service to outsource wedding thank-you notes. While not a business service, it demonstrates the extremes to which we can assign our tasks to others. It seems that there is nothing you cannot outsource.
Well, I can think of one thing that can’t be outsourced – responsibility. When the dust settles around what is kept in-house and what is outsourced, the one undeniable fact is that a company exists for the benefit of the shareholders. Everything from employee policies to customer satisfaction to ethical and legal issues roots back to the impact on shareholder value. These responsibilities stay with the firm regardless of the functions that have been outsourced.
While service levels and costs get the most attention during contract negotiation, security is a responsibility that should not be taken lightly. A significant security responsibility lies with every company – to protect customer and employee data, to ensure the continuity of the business and to protect the intellectual property assets of the company. Each of these can be put at risk in an outsourcing relationship if not properly addressed contractually and operationally.
The outsourcing contract becomes critically important for outlining security responsibilities and penalties for breaches. Plenty of time should be allowed for negotiating the security aspects of an outsourcing contract and time must be allowed for reviews at multiple levels within both companies. To properly address security in an outsourcing contract, a review team should be established to analyze each business process that will be affected by the proposed outsourcing. This review should consider the various risks that could impact each business process, and provide a channel to raise issues to the senior decision-makers. Examples of risk to be considered include:
* Exposure of a company’s sensitive and critical information.
* Exposure of personal information, whether customer or employee.
* Exposure of a company’s intellectual property such as source code, patented processes, etc.
* Relocation of IT equipment from a known, safe environment to an unknown environment.
* No direct control over the vendor’s recruitment process.
* No direct control over business continuity issues for the outsourced processes.
Once risks are identified and understood, controls need to be defined to mitigate and manage the risks. These controls become incorporated into the contract by defining policies, roles and responsibilities, and possibly audits and penalties. These contractual statements may include:
* The information security policy to be used (normally directly based on the client’s own policy and standards).
* Roles and responsibilities (both client and outsourcing provider).
* Mandatory practices, e.g. access control processes, backup and recovery.
* The various service levels for providing confidentiality, information quality and recovery from incidents.
* Rights of inspection and audit.
* Nondisclosure and noncompete agreements for vendor employees (important in offshore arrangements given high turnover rates).
* Venue for legal disputes (particularly important in offshore arrangements, where U.S. courts should be agreed to by the vendor).
* Insurance policies required of the vendor.
* Penalties for breaches of security policy.
By performing a thorough review of the security risks, and establishing contractual and operational controls to manage the risks, you can ensure that you are addressing your responsibility while assigning the workload to another company.




