General discussion
February 21, 2007 at 07:17 PM
tig2

Communicating Security to Out-Source Partners

by tig2 . Updated 19 years, 5 months ago

We live in a time of compliance and governance. In the company I work for, we are challenged in how to communicate our security practices to our Indian outsource partner.

As I see it, we have some pitfalls that we, as Americans, do not understand fully. But we do see that our security requirements are not being adhered to.

Start here- Indian culture is based in the caste system. It is unthinkable for a person of lower caste to try to pretend (read Identity Theft) to be of higher caste.

Add to this that there is no social security system in India… therefore no social security number.

How do we effectively communicate the requirements around security?

Just this week, I found a document from a partner on a shared space detailing his US SSN, address in US, address in India, and banking information- all in clear text. I took the step of eradicating this document after I discussed it with my manager. We cannot have information like this on open drives.

We know that we are taking the step of providing training in the actions that are acceptable and unacceptable. We have various sign-off requirements that tell us if a person has or has not received training. We even request feedback about the training and what information is helpful. We get all the right answers back but we still have the problems.

I am doing everything I can to find cultural barriers to successfully communicating. No matter what I personally might think, the earth is getting flatter and more and more we need to learn and communicate in the language of international business.

What are your thoughts on this and what should my next steps be in trying to overcome the problem?

This discussion is locked

All Comments