Outsourcing Security
June 22, 2010 - 6:58 pm
A secure payment processing gateway goes a long way in protecting merchants security breaches in payment processing. But, merchants must also take great care in protecting security from the inside of the the business operations as well.
Most businesses simply do not have the expertise or budget to adequately protect themselves from the ever increasing risks of security breaches. Therefore, companies are outsourcing security protection to outside vendors.
It’s vital to remember that ultimately security protection responsibility lies with the company, not the outsourced vendor. If and when security breaches occur it, the company bears the consequences.
Consider the following when moving to security outsourcing.
- Consistently monitor the vendor. Executives should appoint knowledgeable staff that has a thorough understanding of the correct procedures and technologies.
- Have multiple departments overseeing the outside vendor. This helps prevent an insider colluding with an outside vendor. Naturally, be sure the departments communicate with each other and with top company executives.
- Read the contracts. Check limitations and exclusions. Know exactly what is covered.
- Have a clear and immediate response plan in place in case there is a breach.
- Verify that the vendor is compliant with all relevant legislation and follows best practices procedures.
- Retain the ability to monitor and independently audit the vendor to verify performance.
- Track contractor performance through statistics such as number of incidents, time taken to respond to incidents, etc

