Procurement Best Practices

Procuring the services of an outside consulting firm or vendor to conduct an objective risk and vulnerability assessment is not an easy task. This is especially true if the assessment is to be intrusive or nonintrusive.

Many organizations desire a rigorous risk and vulnerability assessment that includes the use of tools to find and uncover risks, threats, and vulnerabilities on a production network. This type of intrusive assessment means that the assessor will utilize tools and monitor the IT infrastructure during production hours when tests will be conducted. Some organizations demand that a nonintrusive risk and vulnerability assessment be conducted given the sensitivity and nature of their production systems and environments. In most cases, risks, threats, and vulnerabilities can be identified through careful examination of the IT infrastructure physically, logically, and on-site at the organization's data center and facilities.

When purchasing the outside services of an objective, independent consultant or vendor company to conduct a risk and vulnerability assessment, consider these best practices:

In summary, dealing with consultants and vendor companies can be a tedious and unpleasant experience, especially if you are being sold something, rather than finding a solutions partner. For risk and vulnerability assessments, use of independent or small consulting firms may provide you with the necessary technical and security expertise at a much lower cost. Use of a large consulting firm or vendor company may not be the most cost-effective, but may provide more experience and project references.

The personality of the organization should match the personality of the consultant or vendor company in that the consultant's or vendor's understanding of the project, approach to the project, and style for working with the organization are also factors to consider when selecting an outside consultant or vendor company. The most important evaluation element to consider for hiring an outside consultant or vendor company is how that consultant or vendor reiterates the understanding of the project and their approach for handling the risk and vulnerability assessment.

The consultant's or vendor's ability to articulate this as well as map the project's tasks and deliverables to their approach to the project should be evaluated carefully for relevance to the organization's ultimate project goals and objectives. This is the most important criteria to review and evaluate when selecting an outside consultant or vendor company to perform a risk and vulnerability assessment.

Категории