Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Performance monitoring of colocation vendors |
|---|---|
| Date: | Mon, 5 Dec 2005 06:10:44 -0800 |
On Nov 30, 2005, at 2:42 PM, Dora Mandadjiev wrote:
Hello,
If a company uses a co-location facility for housing its IT infrastructure:
1. What are things that are appropriate and necessary to review/ audit the service provider for on a regular basis (e.g., annually)? Does anyone know of a good checklist or an audit program for such review?
The same thing you would review if it were not outsourced.
Is it appropriate to ask the vendor to provide for review internal policies and procedures for equipment maintenance, incident handling, physical access, etc?Not only appropriate but absolutely necessary.
How should I handle situations when the colocation provider with whom our company has a colocation contract has outsourced the facilities management to another company and says that the maintenance P&Ps are part of the contract b/w the outsourced vendor and them and are confidential?Fire the vendor and explain that the need to fulfill legal and regulatory requirements is absolutely necessary and their confidentiality is less important then you keeping your CEO out of jail.
What is an appropriate way to leverage SAS70 reviews on the vendor?Whatever they cover you should use, however, this is not adequate from a controls point of view in my view.
2. What are appropriate metrics to use to "monitor" the performance of the service provider (if they are providing facility and internet connectivity)?Business metrics - always. I have a book called "Security Metrics" that provides a whole set of metrics that go with the governance structures described in "the Governance Guidebook". But which ones are good for you requires customization to the model you use and your specific needs.
Up-time, power outages, environmental parameters, incidents, etc.Sure - these are 4 out of 4,000 you likely should choose from. The question drives back to the fundamental question of how your business depends on them.
Thanks!
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Risk Analysis for IT Landscape, Fred Cohen |
|---|---|
| Next by Date: | Re: Operational risk, Fred Cohen |
| Previous by Thread: | Performance monitoring of colocation vendors, Dora Mandadjiev |
| Next by Thread: | Operational risk, Tritsaris Konstantinos |
| Indexes: | [Date] [Thread] [Top] [All Lists] |