User:Shawndouglas/sandbox/sublevel1

From LIMSWiki
Jump to navigationJump to search
NSOC-2012.jpg

Many MSSP options exist for labs seeking MSS. (Appendix 2 of this guide provides a list of profiles for top MSSPs to consider.) In some cases, if the lab is already using a public or hybrid cloud provider, that provider may already offer MSS to its customers, providing a certain level of convenience and familiarity to the lab. (For example, both IBM and Cisco, which offer public and hybrid cloud services, are ranked among the top 30 MSSPs in several publications.[1][2][3][4]) However, in some cases it may make sense for the lab to look beyond their cloud provider, particularly if their cloud provider doesn't supply MSS to its clients.

As discussed prior, a knowledgeable and well-run MSSP can provide many benefits to the cloud-based lab, but what should stand out about the MSSP you select? When choosing a provider of comprehensive cloud-based MSS, you'll be looking for not only years of experience managing cloud installations, but also that the provider is able to[5][6][7][8]:

  • demonstrate deep knowledge of cloud-agnostic, industry-relevant best practices and approaches to security frameworks and their implementation;
  • demonstrate deep knowledge of regulatory mechanisms affecting your data and how to approach cloud security based upon those regulatory requirements;
  • describe what certifications, training, and continuing education requirements are met by staff;
  • leverage existing and emerging cloud security tools (e.g., security information and event management [SIEM] software) for automating security processes in a scalable future-proof fashion;
  • validate how their cloud security tools accomplish what they're intended to do, as well as how gathered information is analyzed both automatically and by the provider's analysts;
  • demonstrate how their approaches to security management can fit into or further mold your current IT and risk management strategies;
  • provide transparent pricing (e.g., is it tiered or bundled, based on number of users, something else) and make clear what the service covers;
  • provide examples of existing and past customers willing to give feedback about their experience with the provider;
  • provide a single point of contact to act as a security advocate to you during the entirety of your contract;
  • support not only open-source security management tools, but also be flexible enough to integrate your own proprietary solutions and their associated licenses into the managed service.

Of course, cost will also be of concern. However, a blanket "how much does it cost" question isn't going to produce a simple answer; there will be many variables (e.g., business needs, current solutions, current IT staffing, regulatory requirements, etc.) within your organization that make it difficult for an MSSP to provide a canned response. They will need to respond to your lab’s needs, which may be different from another lab's.[9] Additionally, costs associated with MSS can vary, not only from provider to provider but also based upon each provider's pricing model. Will they charge your lab based upon number of users, number of devices, or some other mechanism? Does the MSSP provide a flat rate for protecting your cloud resources, or do they offer different tiers or bundles of services? And will the MSSP providing cloud-based MMS also manage your non-cloud resources? A "per user" or "per device" approach to pricing may make sense for small labs, but larger organizations may balk at such inflated costs, preferring a flat rate or tiered package of services. Those tiered services may be based on either a user number range or based on a set of offered services.[6]

Ultimately, before approaching an MSSP, your lab will have needed to go through multiple steps internally, stating IT goals, identifying technology and education gaps, and determining a budget to support those goals and gaps. If your lab doesn't have a clear picture of what it has, where it wants to be, and what it will need to get there, it will make selection process even more difficult. As such, your lab may want to consider the request for information (RFI) process as part of your selection process.

References

  1. "Top 250 MSSPs for 2020: Companies 10 to 01". Top 250 MSSPs: Cybersecurity Company List and Research for 2020. MSSP Alert. September 2020. https://www.msspalert.com/top250/list-2020/25/. Retrieved 21 August 2021. 
  2. "Top 250 MSSPs for 2020: Companies 30 to 21". Top 250 MSSPs: Cybersecurity Company List and Research for 2020. MSSP Alert. September 2020. https://www.msspalert.com/top250/list-2020/23/. Retrieved 21 August 2021. 
  3. "Top 15 Best Managed Security Service Providers (MSSPs) In 2021". Software Testing Help. 30 April 2021. https://www.softwaretestinghelp.com/managed-security-service-providers/. Retrieved 21 August 2021. 
  4. "Top 100 Managed Security Service Providers (MSSPs)". Cyber Defense Magazine. Cyber Defense Media Group. 18 February 2021. https://www.cyberdefensemagazine.com/top-100-managed-security-service-providers-mssps/. Retrieved 21 August 2021. 
  5. "How Managed Cloud Security Works, and Why You Might Want It". Trianz. 29 March 2021. https://www.trianz.com/insights/managed-cloud-security-services-how-and-why-it-works. Retrieved 21 August 2021. 
  6. 6.0 6.1 "How Much Does Managed Security Services Cost?". RSI Security. 20 August 2020. https://blog.rsisecurity.com/how-much-does-managed-security-services-cost/. Retrieved 21 August 2021. 
  7. Russell, J. (10 January 2021). "10 Tips for selecting a Managed Security Services Provider (MSSP)". HarmonyTech Blog. https://www.harmony-tech.com/10-tips-for-selecting-a-managed-security-services-provider-mssp/. Retrieved 21 August 2021. 
  8. "How to Choose an MSSP" (PDF). NTT Security. November 2016. https://www.nttsecurity.com/docs/librariesprovider3/resources/us_data_sheet_how_to_choose_an_mssp_uea_v1. Retrieved 21 August 2021. 
  9. Dosal, E. (2 May 2019). "Is Managed Security Worth the Cost?". Compuquip Blog. https://www.compuquip.com/blog/is-managed-security-worth-the-cost. Retrieved 21 August 2021.