SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Outsourcing and Application Service Providers (ASP)

Understand your outsourcer: ISACA

Understand your outsourcer: ISACA

By:  Kathleen Lau  On: 29 Jul 2008 For: Computing Canada Creator
 

Security service firms can’t be relied upon to understand your business or policies, says a conference speaker. What to look for when conducting a security audit.

TORONTO – When it comes to an organization’s information security, having an IT strategy is critical. But surprisingly, one industry expert has encountered several chief information officers who relied on their outsourced IT providers for that responsibility.

“What’s the motivation for the provider to make things better for you?” asked Donna Hutcheson, information technology audit director with Energy Future Holdings Corp. She posed the question to an audience of information security professionals at this week’s ISACA (Information Systems Audit and Control Association) conference in Toronto.

Outsourcing providers cannot be relied upon to understand an organization’s business, know its policies, nor the demands of its leadership, said Hutcheson.

But in the event there is an IT strategy in place, then that strategy should also be subject to an occasional audit, she said. In particular, the organization should examine the problem the strategy seeks to resolve; whether the strategy reaches across, and doesn’t conflict with, all business units; the cost of maintaining the strategy; and whether the outsourcing provider knows of the strategy and is bound by it.

Conversely, an organization that buys outsourced services is often unaware of the complexity of such a relationship and what transpires behind the scenes on the provider side.

Often, an outsourcing provider will in turn outsource to a third party without the knowledge of the organization, said Hutcheson. Should something go awry, the business could find that the lines of communication between it and a third party may not be so direct and easy.

Furthermore, a problem may fail to be escalated or adequately addressed by the provider when, in turn, it has to pay its outsourcer to resolve issues that arise. She recommends including in the outsourcing contract that services cannot be outsourced to a third party.

But communication issues aside, an outsourcer outsourcing to a third party could mean that support for different parts of an organization’s business – IT infrastructure, database management, call centre – get globally dispersed. “What does that do to your contracts? That’s when the cultural issue comes back again and adds to your total cost,” said fellow presenter Patricia Milligan, associate professor with Baylor University’s information systems department.

Performing a forensic analysis across multiple jurisdictions could also prove tricky, added Milligan.

But to begin with, negotiating contracts can be tricky, said Hutcheson, in that negotiators seldom think in the long term. “Negotiators tend to go for what they see is the least cost today,” she said, adding that technology costs generally decrease with time. “So why negotiate a technology contract that locks in today’s prices?” asked Hutcheson.

Contracts should be written for long term endurance, including such things as baseline maintenance, new projects, decommissioning services and applications and adding new services and controls.


Sign up for our Newsletters

 












Print |  Views: 1468   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Recent Canadian IT Jobs




Related Content

The road to better outsourcing
The road to better outsourcingOutsourcing expert and CIO Canada blogger Linda Tuck Chapman offers some sound advice around outsourcing goal setting and planning, and creating healthy buyer/seller relationships.
Billions in outsourcing deals up for grabs in 2007
Billions in outsourcing deals up for grabs in 2007More than A$7 billion worth of outsourcing contracts are up for grabs in Australia this year with many customers opting for the selective sourcing model.
ING outsources IT contracts worth $1,150m
ING outsources IT contracts worth $1,150mBanking and insurance conglomerate ING Group NV has finalized contracts worth CAD$1,150 million (US$994 million) with a consortium of companies to provide workspace services for its 53,000 employees in Europe.
All I want for Christmas is my own corporate cloud
a recent gartner inc. report predicts that while it’s a trend to outsource it operations to third party providers, large organizations will start building their own private corporate clouds. it will be just like outsourcing to a cloud provider like google or
Outsourcing: "lingo-fatigue"!
outsourcing is one of those terms that is widely used but doesn't really have a common definition. there is a difference between buying/selling goods and services, and engaging an outsourcer.outsourcing means bringing in a third party to co-run a part of your business operations. the outsourcer is at the helm of an integral aspect of your core business services or delivery channel. outs
blog comments powered by Disqus