headlinessecurity technology can be complex and time-consuming
to operate and monitor
it is easy to miss events that may indicate
security breaches
commissum works with the client to establish
appropriate levels of management
commissum managing the process for you provides:
removal from your staff of day-to-day specialised and tedious work
a pool of high level expertise
security operators looking at the bigger picture of security events
alerts for high security risks
on call incident response
lower costs - spread over customer community
issues
Security tools and products can be complex and time-consuming
to operate and monitor. The task of reviewing logs and reports can be
tedious and it is often easy to miss events that may indicate security
breaches or other problems. Your security tools should get expert attention,
but possibly not at the level of a full-time person.
Many security services are capable of being managed
by a third party; examples are:
- user management
- password management
- firewalls
- intrusion detection
- anti-virus
- change control
approach
commissum works with the client to establish
the appropriate level of management to meet their requirements. The first
phase is to define the functional requirement, which could encompass man-on-the-ground
management, or advice on automating existing tools and processes to better
enable the client to manage systems internally with limited commissum
assistance. Establishing a fully managed service involves the following
steps:
- establish level of service to meet client business and security
requirements
- estimate resource requirements for commissum and client personnel
depending on requirements
- agree routine reporting schedule
- establish, agree and test escalation procedures
- draw up and agree service level agreements
- draw up confidentiality and liability agreements (include rights
of inspection and audit)
- finalise contract
- operate service
customer benefits
The client is able to benefit from a professional
service backed by a Service Level Agreement:
- day-to-day specialised and tedious work is removed from the client's
staff
- pool of high level expertise made available to the client
- security operators looking at the bigger picture of security events
(e.g. DDoS attacks)
- provision of alerts and specialists on hand to respond to incidents
- costs spread over a community of customers
- no need to recruit expensive security specialists
|
Note: You can download details of this service as a Adobe
Acrobat PDF by clicking on the button above. If you do not already
have Acrobat Reader, you can download it for free from the
downloads page.
|