When outsourcing, don't forget security, experts say
Companies often forget about cultural differences that may affect security
September 21, 2004 12:00 PM ETIDG News Service -
When it comes to outsourcing IT operations to countries such as India and China, companies often focus on slashing costs and gaining productivity but fail to take into account cultural differences that may affect their security, according to experts attending the Gartner IT Security Summit in London today.
"India is seen as an answer when outsourcing applications but is actually a problem in the security space," said Gartner India research vice president Partha Iyengar while moderating a panel on offshoring security.
At issue is not so much the security that outsourcing service providers use to protect companies' systems -- such as firewalls and data backup -- as it is the cultural differences, Iyengar said. For instance, standards of privacy are often looser in India because it's a close-knit society where, say, reading someone else's e-mail wouldn't be considered much of an intrusion, Iyengar said.
This more relaxed attitude toward privacy could have serious consequences when it comes to protecting corporate data, experts on the panel warned. Companies that outsource operations overseas are advised to train local staff to adhere to the company's global privacy standards and to check into the risk of government interception of sensitive confidential information.
"Fifty percent of companies understand that there are security issues with offshoring, but the real issues are cultural and in compliance and regulation," said Lawrence Lerner, senior technical architect of the Advanced Solutions Group at Cognizant Technology Solutions Corp.
Lerner said his company advises its clients to document its processes when outsourcing and get all parties involved to sign off on procedures to ensure transparency. He also suggests performing background checks on local staff.
As a result of high demand by Western companies looking to reduce costs, some outsourcing service providers in India and China are growing rapidly, hiring thousands of new employees in a month."When you are hiring 5,000 people at a time, you need to make sure that they all adhere to the same standards," Lerner said.
R.K. Raghavan, consulting adviser on security at Tata Consultancy Services Ltd., one of India's largest IT services companies, said his firm is feeling the effects of these client demands. "We are bending over backward on security, primarily to cater to our U.S. customers, which are a huge part of our market," Raghavan said.
Tata has recently changed the way in which it performs background checks on potential employees amid volume hiring and increased customer demands.
Previously, the company required two references from each applicant as a security measure but did not ensure that the
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
