Outsourcing Managed Security Services

outsourcing, the hire, train and retain highly qualified …. guidelines to consider when outsourcing network services to reduce protection and ….

More PDF Content

Outsourcing Managed Security Services
Table of Contents
Outsourcing Managed Security Services… 3
Benefits of Engaging an MSS Provider… 4
Risks in Engaging an MSS Provider … 6
How to Use These Practices … 8
Terminology … 11
Acronyms… 12
Practice 1: Content Guidance for an MSS Request for Proposal … 15
P1.1 Business Attributes … 16
P1.2 Service Attributes… 21
P1.3 Security Practices … 28
P1.4 Case Studies … 37
P1.5 Checklist… 38
Practice 2: Guidance for Evaluating an MSS Proposal… 41
P2.1 Business Attributes … 42
P2.2 Service Attributes… 50
P2.3 Security Practices … 52
P2.4 Evaluation Matrix … 55
Practice 3: Content Guidance for an MSS Service Level Agreement … 59
P3.1 General SLA Guidelines … 61
P3.2 Business Attributes … 64
P3.3 Service Attributes… 69
P3.4 Security Practices … 71
Practice 4: Transitioning to MSS… 77
Practice 5: Managing an Ongoing MSS Provider Relationship … 81
Practice 6: Terminating an MSS Provider Relationship … 87
Practice 7: Considerations for Network Boundary Protection as Managed Security Services … 91
Firewall Service… 91
Intrusion Detection System Service … 94
Virtual Private Network Service… 97
Practice 8: Considerations for Vulnerability Assessment as a Managed Security Service … 101
Considerations Prior to Conducting a VA… 102
VA Activities… 104
Post-Assessment Reporting and Consulting Options… 105
Bibliography … 107

Download Outsourcing Managed Security Services pdf from www.cert.org, 121 pages, 509.83KB.