Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    E-Travel Books With MSSP

    By
    Anne Chen
    -
    May 20, 2002
    Share
    Facebook
    Twitter
    Linkedin

      How would you feel if you were spending 40 percent of your annual IT budget on security—software, hardware and people—but your business-to-business customers still insisted on third-party confirmation that your network was locked down? Probably a lot like Geoff Teekema, CIO at e-Travel Inc., who decided last year to outsource some operations to an MSSP, TruSecure Corp.

      So far, Teekema said, although he has chosen not to use the managed security services provider to handle all of e-Travels security operations, the move has enabled his company to reassure its customers that critical information about them in e-Travels systems is safe. Its also had the benefit of helping Teekema reduce overall security costs to between 20 percent and 30 percent of his IT budget, mainly by shifting security-focused employees to other roles.

      “Security is probably one of our biggest expenditures, and we felt this was a fairly inexpensive way to ensure we have the best security processes in place,” Teekema said.

      e-Travel, in Waltham, Mass., isnt the only company turning to an MSSP. Research company Gartner Inc., in Stamford, Conn., estimates that, through 2005, managed security services will be the fastest-growing segment of the security service market. Like e-Travel, most enterprises will continue to control security strategy and policy internally. But many will increase use of shared security services for design, validation, deployment, operation and day-to-day management of security solutions, according to Gartner.

      e-Travel, the e-commerce business unit of Amadeus Global Travel Distribution SA, in Madrid, Spain, originally turned to TruSecure to reduce costs and reassure corporate customers that its networks and systems were well-protected. e-Travel provides electronic travel booking and management services to airlines, travel agencies and corporate customers. Employees of e-Travels corporate customers—230 Fortune 1000 companies—can access their travel profiles and book their trips using personalized portals. As a result, e-Travels Oracle Corp. databases house lots of proprietary data, including employee identification numbers and travel schedules. With so much proprietary data at stake, many prospective customers wanted to do their own full-scale security audits of e-Travels infrastructure.

      But Teekema didnt want nonemployees rooting around in his data center. So he decided he needed an MSSP to audit his company and to provide security certification that would satisfy his customers. The TruSecure managed service, which is subscription-based and costs Teekema “in the low six figures” per year, provides e-Travel with three tiers of security: intrusion detection, internal scanning, and an assessment of security policies and procedures.

      Although TruSecure, of Herndon, Va.—and other MSSPs such as Foundstone Inc., of Mission Viejo, Calif.—also offers a wider range of service up to and including responding to security threats and updates, Teekema decided e-Travel would retain control of managing patches and updates to user names and passwords, as well as management of the companys 128-bit encryption software. Thats because, Teekema said, he wanted e-Travel to retain complete control of its infrastructure.

      During the initial auditing process, TruSecure employees attacked the e-Travel Web site, all of the companys IP addresses and the companys network in an attempt to find weaknesses. The MSSP then moved into e-Travels data center and plugged in security scanners to see what type of damage, if any, a rogue employee or hacker could cause if they were able to get behind the companys firewall. Lastly, all security policies and procedures were analyzed to determine how e-Travel was monitoring its site, how it reacted to potential hack attempts and how it verified that no one was illegally accessing its data.

      “They essentially turned the place inside out and did a full-scale analysis of our setup,” Teekema said.

      So far, Teekema said he has made some changes to his infrastructure as a result of the security audits. He recently implemented intrusion detection software and became more stringent with security procedures. (He declined to say if, as a result of using the service, e-Travel has reduced the number or success of attempted hacks.)

      As part of the service contract, e-Travel also provides TruSecure with an image of its infrastructure, along with a complete list of its software and hardware specifications. TruSecure monitors all software patch releases and alerts Teekema when a new patch needs to be installed. If e-Travel chooses not to install a patch because of application incompatibility, for example, its IT managers are required to document the reason. Those holes are then targeted during the next security audit to ensure the missing patch does not leave e-Travel vulnerable.

      The security audits have enabled e-Travel to earn TruSecures Perimeter Certification. The certification states that e-Travel has met TruSecures requirements for security and protection from external infiltration for its hosted customer information and that the company creates controls to define and enforce internal IT policies and procedures. To remain a certification holder in good standing, e-Travel undergoes the auditing process every three months.

      “The nice thing about using [an MSSP] is that we have a single source for security, and that means one less thing we need to worry about,” Teekema said. “We let them track the patches and look for the vulnerabilities so that we can spend more time on our customers.”

      Anne Chen
      As a senior writer for eWEEK Labs, Anne writes articles pertaining to IT professionals and the best practices for technology implementation. Anne covers the deployment issues and the business drivers related to technologies including databases, wireless, security and network operating systems. Anne joined eWeek in 1999 as a writer for eWeek's eBiz Strategies section before moving over to Labs in 2001. Prior to eWeek, she covered business and technology at the San Jose Mercury News and at the Contra Costa Times.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×