In its publication ITSAP.80.085 on network security logging and monitoring, the Canadian Centre for Cyber Security recommends developing a monitoring plan that "defines the risks to which your organization is exposed; identifies important assets and events that need to be logged and monitored; and specifies your organization's log retention policies, and monitoring processes, procedures, and tools." That plan is the basis for a clear quote.
Short answer
You describe your systems and what must not go down: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. What is monitored, the hours, who receives alerts and the reports are set with you.
What the quote should cover
- The list of monitored items: servers, backups, network equipment, computers, online services
- The events that trigger an alert, and their priority level
- The hours during which alerts are handled, and what happens outside those hours
- Who receives alerts at the provider and in your company, and how
- What the provider does when an alert comes in, and what requires your approval
- The reports provided, their content and frequency
- Log retention and your access to that data
How proactive monitoring works
- Inventory of the systems to monitor and selection of what matters to your operations
- Installation of a monitoring tool or configuration of existing tools
- Definition of the thresholds and events that trigger an alert
- Handling of alerts according to the priorities and hours set in the contract
- Fixes and preventive measures, according to what is included
- Periodic reports and review of thresholds
What is monitored
Monitoring can cover disk space, memory and server availability, backup success, the state of network equipment such as the firewall, patch installation on computers, certificate and warranty expiry dates, or the availability of your online services. Have the quote list them precisely: an item missing from the list is not monitored.
Backups deserve special attention. The Centre's baseline cyber security controls call for backing up systems that contain essential business information and ensuring that recovery mechanisms effectively and efficiently restore these systems from backups (BC.7.1). An alert on a failed backup is useful; a periodic restore test is even more so. For the design of the backups themselves, see Data backup.
Who receives alerts, and when
An alert is only worth something if someone handles it. The quote should specify the hours during which alerts are handled, how priorities are defined and what happens to a serious alert received outside those hours. Do not assume that automated monitoring means a person will step in at any hour: get it in writing, with any service level commitments.
Also specify who in your company must be notified, and for which events. Some actions can be taken without consulting you, such as freeing up disk space; others, such as restarting a server during business hours, should require your approval. Our guide to choosing a managed IT provider details what a service level agreement should contain.
Health monitoring and security monitoring
Proactive monitoring is first about your systems working properly. Security monitoring is something else: according to ITSAP.80.085, it looks for indications of known attacks, unusual changes in system behaviour or unauthorized security-related activities. The Centre states that it "should be conducted by security analysts or a security team, and not by the system administrators that set up and configure the systems."
So ask clearly whether the quote covers only system health or security as well, and who does what. The Centre also recommends centralizing logs and archiving them, which is beneficial during incident detection, response and post-incident recovery. If some of your systems are hosted by a cloud provider, the Centre suggests asking what kind of monitoring is performed, how often log data is reviewed, where it is stored and what log data is available to you.
Reports and provider access
Periodic reports show the state of your systems, alerts received, patches installed and recurring problems. They help you plan to replace equipment before it fails. Ask for a sample report with the quote.
The monitoring tool is installed on your systems and gives the provider broad access. On its page about malicious cyber activity targeting managed service providers, the Centre advises determining how long the provider keeps logs of its activities, how detailed they are and how they are protected, and understanding its patch management practices. Have the quote specify what happens to the tool and your data at the end of the contract.
Questions to ask yourself before requesting a quote
- Which systems stop your operations if they go down?
- During which hours do your operations need the systems to work?
- Who in your company must be notified of a serious problem?
- Are your backups checked today, and by whom?
- Do you need security monitoring in addition to system health monitoring?
- Are some of your systems hosted by a cloud provider?
Pitfalls to avoid
- A vague list of monitored items, or none in the quote
- Alerts sent to a mailbox nobody reads
- Assuming an alert received at night will be handled that night, without it being in writing
- Confusing system health monitoring with security monitoring
- Backups that are monitored but never test-restored
- No access to reports or logs, and no handover of that data at the end of the contract
What to specify in your request
- The number of servers, computers and network devices, and their locations
- The cloud services you use
- Your current backup solution
- Your business hours and critical systems
- The people to notify in your company
- Requirements from a client, insurer or contract that must be met
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
What is the difference between proactive monitoring and technical support?
Technical support responds to problems reported by your employees. Proactive monitoring observes your systems to spot a problem before it is reported, or before it causes an outage. The two are often offered together in a managed IT contract.
Does proactive monitoring cover security?
Not necessarily. It is first about system health. According to the Canadian Centre for Cyber Security, security monitoring should be conducted by security analysts or a security team, not by the administrators who configure the systems. Have the quote specify what is covered.
Are alerts handled at night and on weekends?
That depends on the quote. The hours during which alerts are handled and what happens outside those hours must be written in it. Do not assume that a tool monitoring continuously means a person will step in at any hour.
What reports should we receive?
Periodic reports on system health, alerts received, patches installed, backup success and recurring problems. Ask for a sample report with the quote.
Does software need to be installed on our systems?
Usually, yes: an agent or monitoring tool gives the provider access to your systems. The Centre advises knowing how the provider's activity logs are retained, how detailed they are and how they are protected. Have the quote specify removal of the tool at the end of the contract.