CASP+ Definitions: Outsourcing & Contracting

Outsourcing and contracting in terms of cybersecurity refer to the practice of engaging external vendors or contractors to provide certain cybersecurity services or solutions on behalf of an organization.

This can include outsourcing the management of certain security controls or processes such as firewall management, intrusion detection, and incident response to third-party service providers. It can also involve contracting external consultants or auditors to perform security assessments, penetration testing, or other security-related tasks.

Outsourcing and contracting can help organizations augment their internal security resources and expertise, and can provide access to specialized skills and technologies that may be cost-prohibitive to develop in-house. However, it also introduces certain risks, such as the potential for the third-party provider to compromise the security of the organization’s data or systems, or to fail to adequately fulfill their contractual obligations. As such, it is important for organizations to carefully evaluate the security and privacy risks associated with outsourcing or contracting, and to establish appropriate contractual and oversight mechanisms to manage those risks.