In ITSM.50.030, the Canadian Centre for Cyber Security notes that small or medium businesses may use service providers to "remotely manage their organizations' information technology (IT) infrastructure, cyber security, and other related business operations." It also states that when you use a service provider, "your organization remains accountable for incident response." The monitoring is done by the IT services firm Courtier TI finds for you, not by Courtier TI.
Short answer
You describe your systems and what you want monitored: the Courtier TI team first contacts you to understand your project, then finds the best IT services firm to carry it out. That firm presents its quote to you and, if you accept it, carries out the mandate. A managed security quote should state the systems and logs monitored, the coverage hours you request, how an alert is escalated, the reports provided and how roles are shared with your current IT provider.
What the quote should cover
- The monitored scope: computers, servers, cloud accounts, firewall and other log sources
- The logs collected, where they are kept and for how long
- The coverage hours, as you specify them in your request
- Alert triage and how a serious alert is escalated, and to whom
- What the firm may do on its own, such as isolating a computer, and what requires your approval
- The reports provided and how often
- How roles are shared with your current managed service provider (MSP)
MSP or MSSP: what is the difference
A managed service provider (MSP) runs your IT: support, updates, backups and system health monitoring. An MSSP focuses on security: it looks through your logs and alerts for signs of an attack and notifies you under the agreed rules. One firm can offer both; the quote should then state clearly what falls under each service.
Proactive monitoring is first about system health. According to the Cyber Centre in ITSAP.80.085, security monitoring should be conducted by security analysts or a security team, not by the administrators who configure the systems.
Logs and alerts
In ITSM.50.030, the Cyber Centre says you "need to explicitly define your requirements and responsibilities with regards to log support to identify potential security incidents." It suggests asking the provider which types of logs it can provide, how often it reviews them and whether sensitive log data is stored in Canada.
Also ask whether monitoring covers only known threats or also looks for abnormal behaviour, and how you will be notified of an incident that affects your data.
If you already have an MSP
An MSSP does not have to replace your current provider. You do need to decide who receives alerts, who may act on a computer or an account, and who calls you. Have this split written into the quote and the contract, with a named contact on each side. Your business remains accountable for incident response: the contract should state how each party contributes.
Law 25: what stays with you
If an incident involves personal information, the Act respecting the protection of personal information in the private sector applies to your business, not to the MSSP. Notifying the Commission d'accès à l'information and the persons concerned is required when the incident presents a risk of serious injury (s. 3.5), and every incident must be recorded in a register (s. 3.8). The MSSP can provide the information you need; the decision and the register remain yours. See also incident response.
What to specify in your request
- The number of computers, servers and accounts, and the cloud systems you use
- Security tools already in place, such as antivirus or EDR
- The coverage hours you want and who to contact outside those hours
- Your current IT provider and what it already does
- Requirements from a client, an insurer or a contract
You can then describe your project: the Courtier TI team first contacts you to understand it, then finds the best IT services firm to carry it out. That firm presents its quote to you.
Frequently asked questions
What is an MSSP?
A managed security service provider (MSSP) is a firm that monitors the security of your systems for you: it collects and analyzes logs, triages alerts and notifies you when a suspicious event is detected, under the rules set in the contract.
How is it different from proactive monitoring?
Proactive monitoring is first about system health: disks, updates, backups. Managed security looks for signs of an attack. According to the Canadian Centre for Cyber Security, security monitoring should be conducted by security analysts or a security team, not by the administrators who configure the systems.
Do we need an MSSP if we already have an MSP?
Not necessarily. Some MSPs also offer managed security services; others do not. Ask your current provider what it actually monitors, then state in your request what is missing and who will do what.
What should the quote specify?
The systems and logs monitored, the coverage hours you request, how an alert is escalated, what the firm may do without your approval, the reports provided and how roles are shared with your current IT provider.
Does an MSSP keep our incident register?
No. The confidentiality incident register (s. 3.8) and the notice to the Commission d'accès à l'information (s. 3.5) under the Act respecting the protection of personal information in the private sector remain your business's obligations. The MSSP can provide the information you need to meet them. See incident response.