In Depth
Sevice Level Agreements: Tying the Knot
Service-level agreements are at the heart of most managed information security contracts. But they don't guarantee that buyer and seller are pulling in the same direction.
By Malcolm Wheatley
Massachusetts' own contract with managed security services provider Genuity, for example, calls only "for the vendor to make best efforts to provide the most up-to-date version," he says. Even so, Ritter can see the advantages of a tighter approach: "There's no real reason why such stipulations couldn't be in place, provided that the lawyers understood both the need and the technicalities to phrase a sensible contract," he says.
Managed security services providers aren't too sure, though
And in any case, he adds, there's nearly always more than one way to skin a cat. With many known threats, for example, it's perfectly possible to program the firewall to look for particular data packets and filter out the threat that way
In short, if such apparently simple issues can't be readily decided one way or another, it's difficult for any chief security officer to know if the deal he gets from his managed security services provider is a good one or not.
The mist is clearing
For his part, Massachusetts' Ritter points to draft initiatives developed by the Massachusetts Information Technology Division's Cyber Law E-Government Advisory Roundtable with respect to website and software development. If there's a way forward, it might be there, he believes. With page after page of legalese leavened with healthy dollops of good business sense, they're not documents for the fainthearted. And nor, yet, do they deal with managed security services. But as a model
Absent such progress, the business of managing your relationship with a managed security services provider will remain like nailing Jell-O to a wall. In which case, as the Romans used to say: caveat emptor
Other stories by Malcolm Wheatley
slas
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



