How To

Outsource IT with Caution

Theresa Grant, director of information security for Dow Chemical, answers readers' outsourcing questions.

Page 2

What is your company's risk tolerance?

What is the cost versus the benefit?

Are the greatest economy of scale benefits internal or with a security service provider?

What is the outsourcing strategy of the organization?

Does your internal audit organization have the tools or capacity to manage the outsourcing relationship?

Do you have the necessary internal security expertise and resources, or will you benefit more from looking outside the organization?Q: Which functions of IT security could be effectively outsourced and which should be retained? A: Infosecurity functions that could be effectively outsourced include administrative tasks, server administration and security monitoring. Companies should retain any activities that relate to their governance framework or that are driven by risk assessmentssecurity policies, requirements, strategy and othersand functions that require privileged access.

Theresa Grant

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors