What is a potential concern of using Security-as-a-Service (SecaaS)?
What is a potential concern of using Security-as-a-Service (SecaaS)?
A potential concern of using Security-as-a-Service (SecaaS) is the lack of visibility. When relying on a third-party provider for security services, organizations might have limited insight into the security measures and operations being utilized. This limited visibility can hinder their ability to properly assess security effectiveness, monitor for vulnerabilities or threats, and ensure compliance with regulatory requirements.
A. Lack of visibility. When organizations rely on a third-party service provider for security services, they may have limited visibility into the inner workings of the security infrastructure and operations. This lack of visibility can make it challenging to assess the effectiveness of the security measures, monitor for potential vulnerabilities or threats, and ensure compliance with regulatory requirements. Organizations may have to rely on the service provider's reporting and assurance mechanisms to gain insights into the security posture of their systems and data.
According to Security-Guidance-v4.0, Pg 141, 13.1.1.2, Potential Concerns --> Lack of visibility. Since services operate at a remove from the customer, they often provide less visibility or data compared to running one’s own operation. The SecaaS provider may not reveal details of how it implements its own security and manages its own environment.. Therefore, the answer is A.
(page 141) Lack of visibility. Since services operate at a remove from the customer, they often provide less visibility or data compared to running one’s own operation.
A potential concern of using Security-as-a-Service (SecaaS) is: C. Scaling and costs SecaaS typically operates on a subscription-based model where organizations pay for the security services provided. As the organization's needs grow and more resources are required, scaling the services can lead to increased costs. Additionally, organizations may face challenges in accurately estimating the necessary resources and cost implications, which can result in unexpected expenses.
no not correct check the guide page 140