Choosing a Partner
As applications such as Telephony, PP and Microsoft Live Messaging rapidly converge onto the network infrastructure, security becomes more complex and important. In addition, the industry is faced with strong convergence of networks, systems and security management as companies like Microsoft and Cisco embed more security functionality into their OSS and networking fabrics.
Network access control and other integrity architectures are emerging to take their place in the self-defending network of the future, which means configuration, identity and asset management are going to play larger roles in future managed, secure infrastructure. Also, infrastructure components themselves are subject to security vulnerabilities. Now the proactive 'Assurance' management of those devices themselves becomes as important as managing standalone firewalls and IDSs. This implies that enhanced configuration, security and patching management are going to play increasingly important roles in infrastructure management.
All this means is that careful deliberation needs to be given to the partners used in outsourcing contracts. Organizations cannot have a situation where multiple parties manage the same devices to achieve their respective goals. This can defeat security objectives because too many people are involved.
Many MSSPs will insist on full device control to provide their services. This scenario was suitable for standalone
Firewalls and IDS/IPSs, but will need consideration when the Firewall/IDS/IPS functionality becomes embedded into standard routers. The question of who will then manage the router bits and who will manage the security bits in that device becomes an issue.
Just as applications are converging onto the network, and security is converging into the network and applications/OS, outsourcing functions will converge. Customers will increasingly seek out systems integrators and outsourcers who have skills in network management, desktop and branch office life-cycle management, systems management and configuration management, in addition to world-class security expertise. This may very well spell the demise of the boutique security shop or niche-managed security services player, over time.