In computing, managed security services (MSS) are network security services that have been outsourced to a service provider. A company providing such a service is a managed security service provider (MSSP). The roots of MSSPs are in the Internet service providers (ISPs) in the mid to late 1990s. Initially, ISP(s) would sell customers a firewall appliance, as customer premises equipment (CPE), and for an additional fee would manage the customer-owned firewall over a dial-up connection. According to recent industry research, most organizations (74%) manage IT security in-house, but 82% of IT professionals said they have either already partnered with, or plan to partner with, a managed security service provider. Businesses turn to managed security services providers to alleviate the pressures they face daily related to information security such as targeted malware, customer data theft, skills shortages and resource constraints. Managed security services (MSS) are also considered the systematic approach to managing an organization's security needs. The services may be conducted in-house or outsourced to a service provider that oversees other companies' network and information system security. Functions of a managed security service include round-the-clock monitoring and management of intrusion detection systems and firewalls, overseeing patch management and upgrades, performing security assessments and security audits, and responding to emergencies. There are products available from a number of vendors to help organize and guide the procedures involved. This diverts the burden of performing the chores manually, which can be considerable, away from administrators. Industry research firm, Forrester Research, identified the 14 most significant vendors in the global market in 2018 with its 23-criteria evaluation of managed security service providers (MSSPs)--identifying Accenture, IBM, Dell SecureWorks, Trustwave, AT&T, Verizon, Deloitte, Wipro and others as the leaders in the MSSP market. Newcomers to the market include a number of smaller providers used to protect homes, small businesses, and high networth clients. The IT partner intelligence source compuBase has identified more than 35,000 MSSPs worldwide (without Asia), and this number continues to grow as more VARs become MSPs and more MSPs offer Managed Security Services.
Early history An early example of an outsourced and off-site MSSP service is US West !NTERACT Internet Security. The security service didn't require the customer to purchase any equipment and no security equipment was installed at the customers premises. The service is considered an MSSP offering in that US West retained ownership of the firewall equipment and the firewalls were operated from their own Internet Point of Presence (PoP) The service was based on Check Point Firewall-1 equipment. Following over a year long beta introduction period, the service was generally available by early 1997. The service also offered managed Virtual Private Networking (VPN) encryption security at launch.
Industry terms Asset: A resource valuable to a company worthy of protection. Incident: An assessed occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an asset. Alert: Identified information, i.e. fact, used to correlate an incident.
Six categories of managed security services
On-site consulting This is customized assistance in the assessment of business risks, key business requirements for security and the development of security policies and processes. It may include comprehensive security architecture assessments and design (include technology, business risks, technical risks and procedures). Consulting may also include security product integration and On-site mitigation support after an intrusion has occurred, including emergency incident response and forensic analysis
Perimeter management of the client's network This service involves installing, upgrading, and managing the firewall, Virtual Private Network (VPN) and/or intrusion detection hardware and software, electronic mail, and commonly performing configuration changes on behalf of the customer. Management includes monitoring, maintaining the firewall's traffic routing rules, and generating regular traffic and management reports to the customer. Intrusion detection management, either at the network level or at the individual host level, involves providing intrusion alerts to a customer, keeping up to date with new defenses against intrusion, and regularly reporting on intrusion attempts and activity. Content filtering services may be provided by; such as, email filtering and other data traffic filtering.
Product resale Clearly not a managed service by itself, product resale is a major revenue generator for many MSS providers. This category provides value-added hardware and software for a variety of security-related tasks. One such service that may be provided is archival of customer data.
Managed security monitoring This is the day-to-day monitoring and interpretation of important system events throughout the network—including unauthorized behavior, malicious hacks, denial of service (DoS), anomalies, and trend analysis. It is the first step in an incident response process.
Penetration testing and vulnerability assessments This includes one-time or periodic software scans or hacking attempts in order to find vulnerabilities in a technical and logical perimeter. It generally does not assess security throughout the network, nor does it accurately reflect personnel-related exposures due to disgruntled employees, social engineering, etc. Regularly, reports are given to the client.
Compliance monitoring Conduct change management by monitoring event log to identify changes to a system that violates a formal security policy. For example, if an impersonator grants himself or herself too much administrative access to a system, it would be easily identifiable through compliance monitoring.
Managed Detection and Response (MDR) Unlike traditional MSS, which focuses on perimeter management and alert triage (sending notifications for the client to handle), managed detection and response focuses on rapid threat detection, analysis, investigation and response (the provider actually takes steps to contain the threat).
… excerpt ends here. Continue reading the full article.
