
Subscribe to
Computerworld
or
Other Networking and Internet Stories
July 28, 2005 (Computerworld) -- As U.S. businesses, policy-makers and security experts work to stem the tide of data thefts, an equal or greater vulnerability lurks overseas -- the level of network and physical security at outsourced operations of U.S. corporations.
Cheap labor and increased efficiencies continue to drive major U.S. companies to open and expand offshore operations throughout India, Southeast Asia and Europe. India's National Association of Software and Service Companies reported recently that India's outsourcing industry is creating jobs at the rate of nearly 100,000 a year, and its revenue is growing at more than 40% annually. Analyst firm Gartner Inc. estimates that global spending on offshore outsourcing services will top $50 billion by 2007.
Many of these outsourced operations involve handling and processing customer transactions and sensitive personal information, exposing outsourcing facilities to the same risk of data theft occurring domestically. As U.S. companies increase operations abroad, many aren't ramping up IT or physical security measures at these locations to manage that growth.
In order to prevent data breaches on the magnitude of what has occurred in the U.S., companies must implement strategies to ensure that the same security standards that they place on their corporate data are being required of companies they partner with across the globe to process their customers' financial and personal information.
Several factors magnify the risk of data thefts occurring at outsourcing locations. First, when it comes to outsourcing, U.S. privacy legislation is quite lax relative to European Union regulations. Here, U.S. privacy protections effectively end at the border, placing the onus squarely on the shoulders of the U.S. company if a data breach occurs offshore.
In sharp contrast, European consumers are afforded considerably greater protection by an EU law that permits personal data to be sent offshore only to countries whose privacy laws have been deemed to provide equivalent privacy protection and that have been found to have strong enforcement capabilities.
Similarly, some of the leading outsourcing destinations, such as India, China, the Philippines, Malaysia and Pakistan, lack sufficient privacy legislation. For example, the University of California, San Francisco, Medical Center had a contract with an in-state company to transcribe the dictated notes of doctors and other health care providers. The company, Transcription Stat in Sausalito, Calif., subcontracted the work to a Florida firm that then subcontracted it to a Texas outfit that ultimately hired someone in Pakistan to transcribe the notes, according to the university. Last fall, the medical center received an e-mail from the Pakistani transcriber claiming that she had not been paid and threatening to publicize personal medical records. A partial payment was made the following day, and the transcriber never publicized the information.
India also comes up short with regulations on personal privacy and data. India's Information Technology Act 2000 remains silent on the issues of privacy, protection and regulated use of data. The act in its existing form covers only unauthorized access and data theft from computers and networks with a maximum penalty of about $220,000 and doesn't have specific provisions relating to data privacy. Indian law doesn't cover data interception and computer forgery at all. Thus, data-protection issues primarily remain in an unregulated Indian environment.
In view of the lower wages in outsourcing, one must also consider that the cost to potentially compromise an individual's integrity is also proportionally lower with that same outsourcing partner. In light of this consideration, clearly the security controls set for an outsourcing firm must be more stringent than those that would have been in place had the organization kept the task in-house.
There are several steps U.S. companies can take to secure their outsourcing operations abroad and protect customer data.
First, as we recommend to companies across the globe, a strong security policy must be put in place and followed vigorously. This goes beyond perimeter security to include physical security as well as access and application controls. In addition:
|
|
Print this Story |
|
Send Us Feedback |
|
E-mail this Story |
|
Digg this Story |
|
Slashdot this Story |
|
|
|
|
|
|
|
|
All Zones Application Performance Zone Business Continuity Zone Data Center Management Zone Enterprise-Class Security Zone The File Data Management Zone Grid Computing on Windows Zone Security Management Zone ITIL Best Practices Zone The SAS Zone Storage Virtualization Zone Business Intelligence and Analytics Zone |
|
|
| ||||||||
| ||||||||
| ||||||||
|


| XenServer FREE trial Citrix XenServer is the simplest and most effective way to virtualize and provision servers. XenServer combines comprehensive server virtualization capabilities with unparalleled scalability, performance, economics, and ease-of-use. Based on the open source Xen hypervisor, XenServer delivers fast performance, easy management, and advanced features such as live migration. |

Who needs Mrs. Doubtfire? When it comes to spot-on "advice," we've got Aunt Donna.
|
Accelerate your pursuit of perfection For almost 80 years, Kodak has been helping banks, insurance companies, healthcare providers, government agencies and other businesses produce billions of document images. So Kodak is uniquely positioned to know and deliverwhat customers want: easy-to-use scanners that output the best possible image quality. Download this white paper now!
|

Networking Know-HowFor tips and best practices on building anything in the network, see Sandra Gittlen's regular column. Click here to read the latest column by Sandra Gittlen |
| |
![]()
Troubleshooting Remote Site Networks - Best Practices
Management and remote site employees expect the same level of network service as the headquarters site. However, when IT staff are faced with limited resources to support remote site networks, often the applications, services and performance at those sites is not as robust as the headquarters site. See how to deliver a high level of network service at remote sites using the best practices outlined in this white paper.Read whitepaper now ![]() |
![]()
Super-size your LAN with fiber
Fiber optic technology frees the Local Area Network (LAN) from the confines of a single building, allowing a LAN to extend across a campus or a metropolitan area. Read how the selection of fiber optic components affects repeaterless transmission distance and how one school district used fiber to build a more reliable and more cost effective high-speed, district-wide network. Also, read how Metropolitan Area Network (MAN) ownership may require self-assessment of network performance.Read whitepaper now ![]() |
![]()
Determining the cause of poor application performance
Are users constantly complaining that your network is too slow? Or that they canât connect or can't stay connected? Are network applications hanging and slowing productivity? Do you spend way too much time trying to isolate the source of the problem and to prove that often the issue isn't the network at all but the application? In this on demand webcast, learn best practices and common root causes of application problems using case studies and live network traffic.Watch webcast now ![]() |
| About Us Advertise Contacts Editorial Calendar Help Desk Jobs at IDG Privacy Policy Reprints Site Map |
|
CIO The Industry Standard |


