Saturday, 4 July 2015

Outsourcing and Offshoring as Potential Threats

Should outsourcing and/or offshoring be viewed as potential threats to cyber security?

There are potential risks and benefits associated with Outsourcing and Offshoring.
Outsourcing: Contracting out of a business process to an external party eg. Human Resources and IT services. The reasons why businesses outsource is so that they can focus on the core activities to have a competitive edge over their rivals.
Offshoring: Relocation of a business process to another country eg. Call centres and Customer support.

The advantages of outsourcing and offshoring includes cost savings (Cost is normally the main driver behind outsourcing), Lack of expertise (Outsourcing service providers provides higher quality of service and expertise), Cheaper labour (Provides flexibility as the business does not have to worry about hiring or firing of employees).

The disadvantages of outsourcing include miscommunication between business and vendors, cultural differences,  increased reliance on third parties, lack of in-house knowledge of critical (though not necessarily core) business operations, project failure, service providers subcontracting to other providers and service providers lack of understanding of the client's business.

Outsourcing and Offshoring has its benefits and risks that goes along with it. Businesses need to applying due diligence when deciding on outsourcing or offshoring any part of their business by conducting a proper risk assessment to identify risks.  The business need to build a strong agreement with the service provider such a proper policies and procedure compliance. Business need to include all their requirements in the Service Level Agreement (SLA) to that the service provider can be held accountable for any deviation from the contact. Businesses need to state in the SLA that auditing of service providers information security infrastructure to check for compliance to frameworks such as ISO 17999/27002 or Control Objective for Information and Related Technology (COBIT).

 There will be always be risks associated with businesses outsourcing/offshoring functions. It is therefore my view that it is the businesses prerogative whether outsourcing/offshoring be viewed as potential threat to cyber security.

1 comment:

  1. Routinely all kind of guidance has a comparative reason. These work comparably. We tend to make an immense capability in different reports of same focuses. In addition, everyone will get this http://www.ukraineoutsourcingrates.com/ruby-development-ukraine-rates/site and absolutely unprecedented composed work on a comparative subject.

    ReplyDelete