What is Managed Security?
Managed Security is commonly
referred to as the management and monitoring of vital security protection
systems within the corporate network. Managed Security services are performed
on a 24 x 7 basis by an outside firm who specializes in information security.
The most common systems to be included are the corporate firewall, Intrusion
Detection System (IDS), Perimeter Anti-Virus services, and Content filters for
email and/or web browsing. In order to have an effective security program, it
is essential that data from these key protection systems be evaluated and acted
upon in order to prevent security disasters. Managed Security is the answer to
significantly reducing security risks in a cost-effective manner.
Securing a corporate network can
be quite complicated and time-consuming. It often involves the integration of
vital production systems and sophisticated monitoring tools that poll and
collect extensive amounts of data regarding normal and abnormal network
traffic. Reviewing the data collected and properly acting upon the results
requires a mix of highly skilled security engineers coupled with properly tuned
automated monitoring systems. Many in-house IT managed solutions become either
overburdened with the voluminous amount of false positive alerts or are lulled
into a false sense of security by product features that are installed
incorrectly or are installed in a passive mode. It is this false sense of
security that leads many companies to be at greater risk because the features
are misunderstood or left only to causal review.
It takes extensive training
coupled with installation experience to determine the proper way to install and
fine tune these tools to improve the overall security of a corporate network.
It is only by careful planning, installation, and monitoring that a security
professional can reduce the risk of attack and exposure of corporate data to
unknown sources.
The choice to outsource security
is difficult because it is perceived as a critical function for internal IT
resources. However, corporations outsource physical security to third party
firms, as well as outsource critical data sources to third party processors on a
frequent basis without incident. The value in an outsourced solution is that it
can often improve the level of service, while typically at a lower more
cost-effective expense. Careful oversight and management techniques can help to
ensure a Managed Security solution partner is performing its responsibilities in
the management and monitoring of security events.
Corporations large and small
have begun to understand the value of Managed Security solutions that handle all
the labor intensive responsibilities of management, monitoring, administration,
and support while doing so at a fixed monthly cost. But the true value of the
service is the increased level of protection around the company’s critical
business assets by a team of highly trained security experts.
It is hard to challenge the idea
of getting enterprise-class security protection while reducing the burden on
internal resources all for less than the annual cost of a typical network
administrator.
|