Dec - Feb8Managed Security Services Providers (MSSP) have been a very common route for organizations to fill critical gaps in managing and monitoring their security program. An interested shopper can chose from a wide range of providers and capabilities. A common misconception is that an MSSP can be on-boarded with a "just add water" approach. On the contrary, an MSSP relationship is sometimes more complex than if the organization were to develop the capability in-house. In this article, I will suggest an approach aimed at improving the odds of success. The modern form of the MSSP can trace its lineage back almost two decades. It has evolved from its early days as simple manager of firewalls, through the heyday of IDS, then IPS, to today's multi-mission capable SOC. The modern MSSP manages firewalls, WAF and endpoint protection. It runs vulnerability scanners and tracks remediation. It acts as a cyber threat fusion center and supports incident response. The best SOC operators can never fully appreciate the culture, business drivers, and op-By David Stern, CISO, BGC PartnersThe Path to Drive Success with MSSPDavid SternIn My Opinion
<
Page 7 |
Page 9 >