| | OCTOBER - 2021ENTERPRISE SECURITY8IN MY OPINIONBusinesses are increasingly data driven, and reliant on highly available digital services. Such services must be resilient to a plethora of threats, such as ransomware and theft of intellectual property by an insider. This requires a comprehensive control environment, covering everything from secure hosting to incident response. The resources and capabilities required to achieve this are beyond what many organisations can afford. This is where Cloud Service Providers (CSP) and Managed Security Service Providers (MSSP) step in. These service providers make a high level of capability available through consumption-based pricing. Thus, small enterprises can access best-in-class security, whilst large organisations can worry less about building the necessary skill-base to go it alone. Employing third party services is a cost-effective way of accessing specialist resources and capabilities. However, business risks cannot be outsourced. If consumer data is leaked due to failures of the third-party data processor, it will be the client organisation who will suffer reputational damage and legal liability. Outsourcing security will rarely change this inherent risk impact, but it should reduce the likelihood of a business crippling data breach. This benefit will only be achieved through a clear understanding of the shared responsibilities between Client and Provider. Security processes, when viewed end-to-end, often reveal complex workflows involving multiple people with different responsibilities. Take vulnerability management for example. A MSSP may perform scanning and analysis, while in-house technology teams would do the remediation (i.e. patching or changing configuration settings). Additional responsibilities relating to exception management and compliance reporting should also be factored in. The result is an end-to-end process that spans multiple teams and organisations. This also leads to the risk of unclear accountabilities. Establishing a shared responsibility model, which defines roles, responsibilities and dependencies is an essential foundation for ensuring value from third party services. This is especially important with Cloud Services. CSP's are very good at security. However, the provisioning of cloud resources comes with the responsibility of self-service security configurations, covering access controls, firewall rules, encryption, threat detection, patching frequency, etc. Nowadays, most cloud breaches are the customer's fault, and could have been prevented if available safeguards were enabled. Sadly, many of IS YOUR SERVICE PROVIDER MANAGING YOUR SECURITY RISK? THINK AGAIN!By Steve Williamson, Head of Audit for Information Security and Data Privacy, GSKMBA, CISSP, CCSP, CISA, CRISC, CIPT, CEng FBCSSteve leads the Internal Audit team for GSK, covering Information Security and Data Privacy. He is accountable for providing assurance to the board that security risks are being adequately managed. Steve has worked in IT for over thirty years. His background is in software engineering, and for the last sixteen years he has worked in Security & Risk Management within GSK.
<
Page 7 |
Page 9 >