IT security outsourcing is the process of contracting a third-party security service provider to perform, the full or partial IT security functions of an organization. Little is known about the factors influencing organizational decisions in outsourcing such a critical function. Our review of the research and practice literature identified several managerial factors and legal factors. We found research in IT security outsourcing to be immature and the focus areas not addressing the critical issues facing industry practice. We therefore present a research agenda consisting of fifteen questions to address five key gaps relating to knowledge of IT security outsourcing, specifically effectiveness of the outcome, lived experience of the practice, the temporal dimension, multi-stakeholder perspectives, and the impact on IT security practices, particularly agility in incident response.
翻译:信息技术安全外包是同第三方安全服务提供者签订合同以履行一个组织的全部或部分信息技术安全职能的过程,对影响组织决定将这样一个关键职能外包的因素知之甚少。我们对研究和实践文献的审查查明了若干管理因素和法律因素。我们认为,信息技术安全外包的研究不够成熟,重点领域没有解决工业实践面临的关键问题。因此,我们提出了一个研究议程,由15个问题组成,以解决与信息技术安全外包知识有关的5个关键差距,特别是结果的有效性、实践经验、时间因素、多方利益攸关者的观点以及对信息技术安全做法的影响,特别是对事件反应的敏捷性。