Managed Security Service Provider Massachusetts

A Managed Security Service Provider (MSSP) is becoming an increasingly attractive -- and cost-effective -- security solution for many institutions.

Local Companies

Consultants - Information Security
(781)6411511
391 Totten Pond Road, Suite 101
Waltham, MA
Automation Concetps & Technologies, Inc.
508.285.5080
91 Main Street
Marlborough, MA
EMC Corporation
(508) 435-1000
176 South Street
Hopkinton, MA
Cisco
(978) 244-8000
1414 Massachusetts Avenue
Boxborough, MA
New Boston Management Services
(781) 647-3499
800 South St
Walpole, MA
Philanthropic Advisors
(617) 574-7700
400 Atlantic Ave
Boston, MA
Drought Sandra & Associates
(617) 630-1600
80 Ober Rd
Newton, MA
Arlington Storage Corporation
(617) 267-7600
535 Boylston St
Boston, MA
Spectrum Partners Ltd
(781) 444-9804
41 Chapel St
Needham, MA
S & P Consultants Inc
(508) 586-7850
700 W Center St
West Bridgewater, MA










By Tom Schmidt



Effective security monitoring and management entails combining advanced technology with expert human analysis. And today's highly complex threat landscape requires IT teams to continuously monitor systems while remaining up-to-date on all potential vulnerabilities. Yet, many small and midsize financial institutions often lack the time, expertise, and technical resources to maintain effective security on a 24/7 basis. For these reasons, outsourcing security to a Managed Security Service Provider (MSSP) is becoming an increasingly attractive -- and cost-effective -- security solution for many institutions.


This article examines the key elements of managed security offerings and provides guidance on how to select a managed security service provider that will strengthen an institution's security posture.


Demystifying security management vs. monitoring
Given the complexity of today's threat landscape, the integration of security management and monitoring practices is necessary to enable a timely response to intrusions. A high- quality MSSP will supplement the management and maintenance of security devices, such as firewall, intrusion detection systems, servers, and routers, with real-time monitoring of all data generated by those devices. This human analysis is critical to anticipating and preventing attacks. And an MSSP that can offer the right combination of human expertise and technology will allow small and midsize financial institutions to focus on their core businesses while maintaining an effective security posture.


Specifically, security management should provide the following capabilities:



  • Fault management This function provides regular checks of devices to detect potential problems, notification of failures, and guidance to remediate problems as well as status reports detailing the activity of security devices over specified periods of time.

  • Configuration management This usually includes modification and upgrades of operating systems and security device applications, policy and signature changes to security devices, and periodic reports summarizing all upgrades and changes performed.

  • Performance management Performance management requires collecting and presenting all statistics pertaining to an institution's security devices, such as the speed and efficiency of its network, identification of bottlenecks hindering performance, and consolidated reports featuring log data generated by the security devices.

In terms of comprehensive monitoring, services offered by an MSSP should include:



  • Data collection and normalization This process ensures that data collected by an institution's security devices is translated into a standardized format, which enables MSSPs to isolate and analyze malicious activity regardless of the device's brand or type.

  • Data mining Highly sophisticated data mining is necessary to provide cross-correlation of malicious activity. An MSSP must have the ability to scale its data mining abilities and to continuously refine existing queries to detect threats.

  • Automated security event correlation This function enables MSSPs to group malicious activity by predefined criteria such as attack source, type, and destination. In the absence of automated correlation, security experts would have to piece together attack sequences by manually screening millions of lines of security data.

  • Expert response to events In response to a security breach or threat, analysts must choose a course of action ranging from client notification to alerting the authorities.

  • Event reporting This function entails establishing a reporting process to notify institutions about security events detected on their networks. This type of reporting can be handled through a variety of methods such as immediate communication, email, web portal updates, periodic reports, or any combination of the above.

Distinguishing security monitoring claims
It may be somewhat confusing for institutions to determine what specific services are included in an MSSP's offerings. The following are some common security monitoring claims made by MSSPs:



  • Up-time monitoring This means that an MSSP will ensure that a security device is operating, but it doesn't go as far as identifying and preventing attacks. A high-end MSSP will provide this function as part of its security management.

  • Log redirection Some MSSPs offer this capability as an alternative to data mining and correlation, thus putting the onus on the institution to review data and identify suspicious activity.

  • Data consolidation This capability allows MSSPs to collect security data from disparate devices and consolidate it into a single view. However, without automated processes capable of connecting the pieces, this function alone cannot detect and respond to threats in a scalable fashion.

  • Manual correlation MSSPs that lack the technology to automate correlation often offer to perform correlation by manually screening logs for signs of malicious activity. However, manual correlation is not as reliable as automated correlation in reconstructing network attacks.

The right MSSP can make a difference
Small and midsize institutions seeking to outsource their security management and monitoring should consider the following criteria when choosing an MSSP:



  • Longevity Institutions will want to look for a vendor with a large customer base and a reputation for delivering high-quality services over a long period of time.

  • Annual revenues MSSPs with yearly revenues of $10 million or more are best positioned to support growth and enhancement of services.

  • Breadth of channel partners MSSPs that have solid partnerships in place are able to devote more funds to research and development while supplementing their offerings with those of their partners.

  • Breadth of services Best of breed MSSPs will offer a complete security management and monitoring solution, including managed firewall, intrusion detection, antivirus, vulnerability assessment, and consulting services.

  • Security management process Leading MSSPs will provide a variety of attack notification methods and incident response services enabling institutions to mitigate risks in real time.

  • Auditing A reputable MSSP will have third-party auditor validate and certify its facilities, processes, and procedures.

  • Technology and expertise Expert human analysts are necessary to distinguish between real and false threats and therefore should support the technology used to correlate individual signs of malicious activity.

  • Reporting High-quality MSSPs will provide thorough reports, including detailed log data, recommended responses, information on any changes or upgrades made to the security devices, and updates on the latest threats.

  • Security operation centers To remain abreast of the latest threats and to ensure business continuity, MSSPs need to operate multiple security operations centers, from which they can monitor and manage security issues for their customers.

Conclusion
The recent growth of online fraud and the spread of spyware and adware are constantly threatening the security posture of small and midsize institutions. Maintaining the necessary vigilance against these threats requires costly investments in staff, IT systems, and training. Leveraging the capabilities of a managed security service provider allows these institutions to focus on their revenue-generating core competencies while achieving a stronger security posture.


Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Consultants - Information Security

(781)6411511
391 Totten Pond Road, Suite 101
Waltham, MA

Related Articles
- Steps to Safer Virtual Servers Massachusetts
At last week's Black Hat conference, virtualization security was one of the hottest topics and sources of debate. If you're trying to get a grip on how your enterprise's virtualization security stacks up, consider this advice from Chris Whitener, chief security strategist, HP Secure Advantage.
- Managed Hosting Service Options Massachusetts
- Making the Case for Managed Security Massachusetts
- Choosing an Internet Service Provider Massachusetts
- Managed Hosting Massachusetts
- Web Hosting: Linux vs.Windows Massachusetts
- Finding the Right Internet Access Provider Massachusetts
- Benefits of Managed Hosting Massachusetts
- Virtual Fax Massachusetts
- Website Securities Massachusetts
Regional Articles
- Managed Security Service Provider Acton MA
- Managed Security Service Provider Agawam MA
- Managed Security Service Provider Allston MA
- Managed Security Service Provider Amesbury MA
- Managed Security Service Provider Amherst MA
- Managed Security Service Provider Andover MA
- Managed Security Service Provider Arlington MA
- Managed Security Service Provider Attleboro MA
- Managed Security Service Provider Beverly MA
- Managed Security Service Provider Billerica MA
- Managed Security Service Provider Boston MA
- Managed Security Service Provider Braintree MA
- Managed Security Service Provider Bridgewater MA
- Managed Security Service Provider Brighton MA
- Managed Security Service Provider Brockton MA
- Managed Security Service Provider Brookline MA
- Managed Security Service Provider Buzzards Bay MA
- Managed Security Service Provider Cambridge MA
- Managed Security Service Provider Charlestown MA
- Managed Security Service Provider Chelmsford MA
- Managed Security Service Provider Chelsea MA
- Managed Security Service Provider Chicopee MA
- Managed Security Service Provider Danvers MA
- Managed Security Service Provider Dedham MA
- Managed Security Service Provider Dracut MA
- Managed Security Service Provider East Falmouth MA
- Managed Security Service Provider East Weymouth MA
- Managed Security Service Provider Easthampton MA
- Managed Security Service Provider Everett MA
- Managed Security Service Provider Fairhaven MA
- Managed Security Service Provider Fall River MA
- Managed Security Service Provider Fitchburg MA
- Managed Security Service Provider Foxboro MA
- Managed Security Service Provider Framingham MA
- Managed Security Service Provider Franklin MA
- Managed Security Service Provider Gardner MA
- Managed Security Service Provider Gloucester MA
- Managed Security Service Provider Haverhill MA
- Managed Security Service Provider Hingham MA
- Managed Security Service Provider Holyoke MA
- Managed Security Service Provider Hyannis MA
- Managed Security Service Provider Hyde Park MA
- Managed Security Service Provider Jamaica Plain MA
- Managed Security Service Provider Lawrence MA
- Managed Security Service Provider Leominster MA
- Managed Security Service Provider Lexington MA
- Managed Security Service Provider Longmeadow MA
- Managed Security Service Provider Lowell MA
- Managed Security Service Provider Ludlow MA
- Managed Security Service Provider Lynn MA
- Managed Security Service Provider Malden MA
- Managed Security Service Provider Marblehead MA
- Managed Security Service Provider Marlborough MA
- Managed Security Service Provider Mattapan MA
- Managed Security Service Provider Medford MA
- Managed Security Service Provider Melrose MA
- Managed Security Service Provider Methuen MA
- Managed Security Service Provider Middleboro MA
- Managed Security Service Provider Milford MA
- Managed Security Service Provider Milton MA
- Managed Security Service Provider Natick MA
- Managed Security Service Provider Needham MA
- Managed Security Service Provider New Bedford MA
- Managed Security Service Provider Newburyport MA
- Managed Security Service Provider Newton Center MA
- Managed Security Service Provider North Adams MA
- Managed Security Service Provider North Andover MA
- Managed Security Service Provider North Attleboro MA
- Managed Security Service Provider North Dartmouth MA
- Managed Security Service Provider Northampton MA
- Managed Security Service Provider Norton MA
- Managed Security Service Provider Norwood MA
- Managed Security Service Provider Peabody MA
- Managed Security Service Provider Pittsfield MA
- Managed Security Service Provider Plymouth MA
- Managed Security Service Provider Quincy MA
- Managed Security Service Provider Randolph MA
- Managed Security Service Provider Revere MA
- Managed Security Service Provider Roslindale MA
- Managed Security Service Provider Salem MA
- Managed Security Service Provider Saugus MA
- Managed Security Service Provider Scituate MA
- Managed Security Service Provider Shrewsbury MA
- Managed Security Service Provider Somerville MA
- Managed Security Service Provider South Hadley MA
- Managed Security Service Provider South Weymouth MA
- Managed Security Service Provider Southbridge MA
- Managed Security Service Provider Springfield MA
- Managed Security Service Provider Stoneham MA
- Managed Security Service Provider Stoughton MA
- Managed Security Service Provider Swampscott MA
- Managed Security Service Provider Taunton MA
- Managed Security Service Provider Tewksbury MA
- Managed Security Service Provider Walpole MA
- Managed Security Service Provider Waltham MA
- Managed Security Service Provider Watertown MA
- Managed Security Service Provider West Roxbury MA
- Managed Security Service Provider West Springfield MA
- Managed Security Service Provider Westborough MA
- Managed Security Service Provider Westfield MA
- Managed Security Service Provider Westford MA
- Managed Security Service Provider Weymouth MA
- Managed Security Service Provider Winthrop MA
- Managed Security Service Provider Woburn MA
- Managed Security Service Provider Worcester MA

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History