The process of selecting and implementing a network-security solution involves three types of activities: gathering information about both your own organization and potential security vendors; obtaining approval from decision-makers; and properly deploying and maintaining your choice solution.Steps for deploying network-security applications, tools and services are broadly the same,whether you're buying a next-gen firewall, a cloud access security broker (CASB), an intrusion-detection system. Similar procedures can also be applied to other aspects of information security.Here are 10 steps you should take when picking out and setting up a network-security solution.
1. Conduct a thorough inventory, vulnerability audit or risk assessment of your organization.
You won't get an idea of what you need until you perform due diligence on your own organization's strengths, weaknesses, and ability to grow. Whether you call it an audit, an assessment, or an inventory, you'll want to make sure you can fully answer the following questions. Don't forget to query every stakeholder in your organization.- What is your organization's threat model?
- Who would its most likely attackers be?
- What are your organization's network-security weak spots?
- How many of your employees work remotely, and how often?
- What kind of rules and regulations govern your organization's business activities?
- What kind of network security model do you use? Is it perimeter-based or zero-trust?
- Do you allow employee-owned devices on the company network? What if they're working from home?
- What kind of assets do you have in the cloud? How recently were they migrated there?
- What is your organization's 5-year growth plan, and will its network-security needs change?
- Are there any network-security appliances that need to be replaced?
- Are there any critical vulnerabilities that need to be patched?
2. Determine what kind of additional network security you need, and what's possible.
Do this only after completing the internal due diligence, which should give you a much better idea of what you need.For example, if you're still using an on-premises firewall appliance, it might be time to move up to a next-generation firewall. If you're new to the cloud, then you'll want some cloud-native security tools. And if you're using a perimeter-security model, you ideally should upgrade to a zero-trust model — but do you have the staff time and expertise to do so?Also check to see whether you have existing network-security tools or services that could be repurposed to meet some of your needs.3. Determine what your organization can afford and get approval for that amount.
In some ways, this is the most crucial step, because it will determine what you can and can't buy. Then go over the list of network-security tools and services you need or want and rank them in order of highest priority, starting with the ones you feel are most immediately necessary.4. Research and compare vendors and their solutions, tools, and pricing.
Find out who has what you need, and how much it costs. You'll be conducting a lot of research on your own, but you should also reach out to other organizations in your industry or similar fields. What are the other organizations using, and what can they recommend?For each potential solution, you'll also want to find out:- How scalable is it?
- How easy is it to use?
- How well would it work with your existing tools?
- What would be the total cost of ownership, including support, maintenance, and staff training?
- Would it affect your regulatory-compliance requirements negatively or positively?
- If you need more than one networking-security solutions, are there multi-purpose bundles — often called unified threat management — that could save you money?
5. Make a shortlist of potential vendors and interrogate them.
Once you've narrowed down the possible solutions to a handful, it's time to grill the vendors. You're about to enter a long-term relationship with at least one of these firms, so don't be afraid to ask tough questions like the ones below.A good networking-security vendor will be happy to answer these (and many more):- Does the vendor provide 24/7 support and response? If so, how much extra does it cost?
- Does it offer staff training for the solution you're thinking of buying? How much would that cost?
- Does the vendor provide help with deployment and implementation? Does that cost extra?
- Does the vendor have experience with other organizations in your industry?
- Is the vendor familiar with the forms of compliance your organization is subject to?
- How many clients does the vendor have?
- What is the vendor's typical client profile?
- Are there any new features or functions on the way for the solution you're considering?
- What is the vendor's 5-year development plan?