Managed security service providers explained

November 2003 Asset Management

A managed security service provider (MSSP) offers outsourced information security to businesses, small and large. The type of services offered by the MSSPs can be clearly split into managed services and monitoring services.

Managed services

Managed services typically involves the comprehensive management of one or more devices (such as firewalls and intrusion detection) within the customer's network. A strict service level agreement (SLA) will determine the interaction with the customer in terms of change control, recommendations, etc. Typically these services include setting up devices, device configuration, updating software and changing rule sets. What managed services should include:

1) Architecture design.

2) System deployment.

3) Configuration management.

4) Software updates.

5) Notification of EOL products.

6) Health and performance monitoring: These services should be offered for firewall, network/host intrusion detection and anti-virus.

Monitored services

Monitored services are more tailored towards offering as close to realtime monitoring and analysis of events as possible. The events in question are generated by devices and can occur at a number of network access points. It may be helpful to compare the monitoring of a network to the way a physical security company monitors a home, in that an event occurs when one of the sensors is breached, setting off an alarm in the control room to which the company then responds.

The monitoring service is controlled with an SLA, having more emphasis on the intelligent analysis of inputs, alerting and escalation. Analysis refers to the identification of an event, subsequent comparison to a known database of events which make up an incident and then the interpretation or categorisation of security incidents or alerts in a specific environment. Reporting of the correlation and trends is included in the monitoring service.

What monitored services should include:

1) Collection of data - this can be in the form of system logs or agent (device) based collection.

2) Aggregation of data - meaning the aggregation of multiple device data into one database.

3) Secure communication - the data sent from the customer site must be encrypted.

4) Correlation - the ability to correlate information from various devices.

5) Analysis - the ability to analyse the data from events to incidents to alerts.

6) Escalation - an ability to produce a trouble ticket in order to escalate events and track progress.

These services should be offered for firewall, network/host intrusion detection and antivirus.

Chris Davis, executive, NamITrust (Enterprise Security Solutions Provider at NamITech)
Chris Davis, executive, NamITrust (Enterprise Security Solutions Provider at NamITech)

For more information contact Chris Davis, NamITrust, 011 458 0081, [email protected], www.namitech.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AI making South African roads safer
Asset Management Transport (Industry) AI & Data Analytics
Driver fatigue is a significant contributor to road accidents globally. While reliable statistics for South Africa are hard to come by, it has been estimated that fatigue is a factor in 25% - 30% of fatal crashes.

Read more...
Simplified fire and facilities management from one screen
Fire & Instrument Services Facilities & Building Management Fire & Safety Asset Management
Fire & Instrument Services (F&IS) and Scansoft are simplifying the complexities of facilities management, including fire safety, with iBMS Adrenaline, an integrated building and facilities management system enabling companies to monitor, control, and manage system hardware through a single interface.

Read more...
Three-quarters of cars sold in 2023 had embedded telematics
IoT & Automation Asset Management
A new research report from the IoT analyst firm, Berg Insight, shows the number of telematics service subscribers using embedded systems will grow at a compound annual growth rate (CAGR) of 14,6% 2023 to 2028.

Read more...
Vivotek unveils new AI RealSight Engine
AI & Data Analytics Asset Management
Vivotek has announced an upgrade to its AI security solution that transforms images captured by network cameras into clear, visible facial images under any lighting conditions. Even in backlit environments, facial expressions are rendered clearly.

Read more...
Natural catastrophes and fire risks top concerns
Security Services & Risk Management Asset Management Residential Estate (Industry)
Natural disasters are the highest risk in the real estate industry, followed by fire and explosions, and then business interruption. Estates must prioritise risk management and take proactive measures to safeguard their assets, employees, and reputation.

Read more...
Building a solid foundation
Alwinco Security Services & Risk Management Asset Management Residential Estate (Industry)
Understanding the roles of a Risk Assessor and a Risk Manager is like building a solid and secure foundation in the security world. Andre Mundell makes it easy to understand.

Read more...
Simplify AARTO compliance for fleets
Guardian Eye IoT & Automation Asset Management Transport (Industry) Logistics (Industry)
While there are challenges around the management and implementation of the AARTO Amendment Act, there are also benefits that need to be understood today to ensure compliance and value tomorrow.

Read more...
Logistics operators stand up to safety challenges
Logistics (Industry) Asset Management Transport (Industry)
The second annual Webfleet Road Safety Report for 2023 outlines common safety factors, challenges and solutions that South African transport operators face; deteriorating roads, poor vehicle maintenance, congestion and driver fatigue are common challenges.

Read more...
People screening goes mobile
Xscann Technologies News & Events Asset Management
Xscann Technologies has delivered a new mobile solution with added value for people screening. This turnkey solution requires no civil works as it is an all-in-one complete body scanning solution built in a shipping container.

Read more...
Securing road transport across Africa
Technews Publishing Editor's Choice Asset Management Security Services & Risk Management Transport (Industry) Logistics (Industry)
SMART Security Solutions spoke to Filipe de Almeida, the Portugal & Spain Regional TAPA EMEA Lead, and Massimo Carelle, the TAPA EMEA Africa Region Lead, about securing transport and logistics in hostile environments.

Read more...