Security News Letter

May 17th, 2004

 

  Back Home Up Next
   Download ZoneAlarm Pro

 Download ZoneAlarm Pro Here

Download eEye's Retina Vulnerability Scanner Here
 Jumpline.com VDS Web Hosting

 

 Kaspersky Anti-Virus: Install & Feel Safe!

Gartner warns of security risks in outsourcing
New Delhi, Deepika Global

 Calling for caution in outsourcing to low-cost countries, IT analyst firm Gartner has said companies must identify and manage the security risks before signing any offshoring agreement.

The key to successful and secure outsourcing agreements is understanding the security and privacy risks for a business process, application or technology function early in the outsourcing decision process, said senior analysts at Gartner Inc.

''An enterprise's security staff should be at the table from the start of the process and throughout the life cycle of the outsourcing deal. The security staff should be included in the operations management functions, working with the vendor's delivery management staff, as well as the strategic planning function where standards, architecture and integration decisions are made,'' Gartner said.

The analysts recommend that large enterprises audit prospective enterprise service providers (ESPs) to ensure that the policy and controls around the outsourced functions or systems meet the enterprise's security standards.

Enterprises that can't take on the task of conducting a security audit should require ESPs to provide evidence of an audit by an independent third party, they said.

When audits are not available, enterprises should use scanning tools or services to ensure that the ESP does not have vulnerabilities in the applications and network gateways facing the Internet, Gartner said.

''Even when audits are available, periodic scanning of the ESP is necessary to ensure baseline profile is maintained.

''Outsourcing decisions require careful analysis of what requirements must be extended beyond the enterprise, and planning to verify and monitor the ESP's ability to meet them,'' said the analysts.

Offshore outsourcing requires even greater care in several areas, such as the degree of governmental access to, or control over, the service provider, as well as over the customer's data, Gartner added.

 

 

Security Products:

HIPAA Step by Step Training

April 20th and 22nd classes are closed out Additional class May 20th 

 

 

PestPatrol is a powerful security and personal privacy tool that detects and eliminates destructive pests like trojans, spyware, adware and hacker tools. It complements your anti-virus and firewall software, extending your protection against non-viral malicious software that can evade your existing security and invade your personal privacy. These pests often lurk silently on your computer until something – or someone – sets them off. When that happens, you could lose passwords, personal data, credit card numbers, and - if you telecommute and connect to your office via a VPN - open up a back door for the hacker into your entire company network. Click here for Pest Patrol

 

Intrusion Detection Systems

bulletIntruvert

Vulnerability Scanners

bullet

eEye's Retina

Firewalls

bulletNetscreen
bulletCheckpoint

Management

bulletSolarWinds

Virus Control

bulletMail Marshall

Services

bulletSecurity audit
bulletPerimeter Vulnerability Scan
bulletRouter/ switch optimization for security
bulletFirewall checking and configuration
bulletVPN Design and Implementation
bulletNetwork design
bulletnetwork based application analysis
bulletNetwork Baselining
bulletSecurity baselining

 

 

  BlackICE PC Protection

Back Home Up Next

This mailing has been performed by Aavex Technology Corporation
42w588 Still Meadows Lane, Elburn IL 60119 USA,  630-365-0025 in compliance with the "CAN-SPAM Act of 2003",  approved and signed by the president of The United States of America on Dec. 16, 2003. For this reason, this email cannot be considered SPAM This newsletter contains commercial advertisement.

 

 

Copyright © 2004 Aavex Technology