Advertisement
Promo

Become a member of the ZDNet UK community

(ISC)2

View blog's RSS Feed

Security Profession blog

Comment and discussion about the security industry of interest to the security professional. Blogs will be submitted by (ISC)2's management team and Advisory Board members.

Monday 22 June 2009, 10:56 AM

Does offshoring or outsourcing increase the data privacy challenge?

Posted by (ISC)2

Last week’s IDG Research Services survey commissioned by RSA highlighted the lack of strategy in place in most organisations for outsourcing business services and information to the cloud. It is a reminder that offshoring and outsourcing present a real challenge to data privacy and data protection but is the risk any more than the risk of data that is not outsourced or offshored?

There are many risks associated with offshoring and outsourcing. The information security risk combined with operational risks including the risk of vendor concentration should determine the direction and pace of the offshoring strategy. Information security professionals must apply industry standard confidentiality (integrity, availability) principles in a risk assessment to ensure that corporate data is not exposed to unnecessary and unforeseen risk. For those professionals working in multi-national organisations, the topic of cross border data movement and data protection zones are not new. However, if data is made accessible to third party vendors or other combined legal entities (captives), the involvement of Legal professionals is paramount to understand processing and disclosure principles and policy.

The offshoring and outsourcing risk assessment may then reveal that existing cross border and service provider policies and standards are inadequate even for existing business processes. Thus confirming that outsourcing does not increase risk, but can actually reduce risk, by improving internal controls.

For Firms and organisations with a complex mix of environments and vendors, control “edge” solutions can be developed for the handling of data, based on “need to know” and “least privilege” principles, delivering sensitive data at the very last minute in the process, and linked to pre-defined and agreed data disclosure rules.

Offshoring and outsourcing programmes may increase the complexity of the environment, and can also increase the burden of supervision but do not increase information security risk. There is no hype with offshoring and outsourcing, rather basic control principles apply.

Alessandro Moretti, CISSP, Member of the ISC)2European Advisory Board and Executive Director, UBS Investment Bank, IT Security Risk Management.


(ISC)2

This member is ranked #86 in our top 100

  • (ISC)2
  • n/a
  • Member since: February 2008

Site Activity Rating 3

Contacts

Number of Contacts: 1

Contacts' Latest Discussions

Number of Tracked Discussions: 122

Karen Friar Karen Friar

Thanks for the catch

Monday 2 November 2009, 6:00 PM

2 comments
Karen Friar Karen Friar

Disappearing comments and blog posts

Tuesday 29 September 2009, 9:36 AM

5 comments
Karen Friar Karen Friar

Windows 7 versus Vista, XP

Thursday 6 August 2009, 11:40 AM

1 comment

Contacts' Latest Blogs

Number of Contacts Blogs: 1


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters