SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> IT Workplace >> Consulting and Contracting

Uniform security for a diverse outsourcing world

Uniform security for a diverse outsourcing world

By:  Mathias Thurman  On: 08 Mar 2009 For: Computerworld US(NA) Creator

Mathias Thurman follows the same security procedures wherever his company's partners are located. From his perspective, the only difference is in the local cuisine

I'll be traveling again in the next few weeks, this time to Vietnam. We've been outsourcing some of our operations to low-cost nations for years: Russia for source-code development, India for help desk services and China for manufacturing, among others.

Vietnam is new to the list, but as I stressed during the meetings about this engagement, there are no special security considerations. We follow the same procedures wherever our partners are located. From my perspective, the only difference is in the local cuisine.

To enhance security as my company works with third parties, I wrote a policy and had it ratified by my CIO. It sets the security requirements for all partner connections, including physical security. It also lays out audit requirements and contains some contractual verbiage specifying the partners' responsibilities.

The policy is actually quite simple: Any partner connection to our company's internal network requires my approval, and my approval hinges on successful compliance with our partner connectivity policy.

A first visit to a partner is crucial, since it sets the stage for the relationship. It's my opportunity to demonstrate the importance my company places on the protection of its intellectual property and the integrity of its network. After all, visiting a country on the other side of the world isn't as easy as driving across town.

So here's my agenda for my first visit with any new partner. My company's policy states that a secure connection must be established between the partner and our company. We typically accomplish this via a small Juniper firewall on the partner's premises and a VPN tunnel between it, and a much larger firewall at our headquarters or a closer regional office. This allows us to maintain control of all the IP addresses, ports and protocols involved in data traffic between the partner and our internal network.

We also require that all Internet connections be routed through our gateways, not the partner's. We learned about the need to do this the hard way, after various partners' employees used their companies' Internet connections to steal our intellectual property.

We mandate that the partner's systems be logically separated from its company network and that all systems have all the latest patches and employ the leading antivirus software. What's more, no unnecessary security software (such as sniffing, scanning or password-cracking utilities) can be installed on any of the systems.


Sign up for our Newsletters












Print |  Views: 923   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mathias Thurman Mathias Thurman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Environmental control systems lack strong security
Environmental control systems lack strong securityA task force is attempting to make building control systems more secure. An observer says its a start, but specific standards are needed
Wireless VPNs not as safe as you'd want
Wireless VPNs not as safe as you'd wantPeople tend to fixate on the "private" in virtual public network. Users sitting in Starbucks work on their laptops thinking they're using a VPN so it's safe. It's not. Here are some tips for the CISO or CSO on how to select a safe and secure VPN
ForeScout updates NAC box
ForeScout updates NAC boxCounterACT’s dissolving client works by initiating an outbound SSL connection from the PC back to the NAC appliance, and was developed to cope with personal firewalls on visiting PCs.
Summarizing CopyCamp 2 while looking forward to CopyCamp 3
tuesday evening and wednesday all day was the second copycamp. the first copycamp was held in september 2006, and i actively participated in both. the first good news is that all the language coming out of the organizing committee is that they already have a desire for there to be a third, so this may become a yearly event.the format is of an unco
blog comments powered by Disqus