A small company that does not have security staff wants to improve its security posture. Which of the following would BEST assist the company?
Correct Answer: A
The company doesn't have IT Staff. So if they want security, they need a MSSP (Managed Security Service Provider).
Managed Security Services Provider (MSSP) - a means of fully outsourcing responsibility for information assurance to a third party. This type of solution is expensive but can be a good fit for an SME that has experienced rapid growth and has no in-house security capability. Of course, this type of outsourcing places a huge amount of trust in the MSSP. Maintaining effective oversight of the MSSP requires a good degree of internal security awareness and expertise.
There could also be significant challenges in industries exposed to high degrees of regulation in terms of information processing.
A SOAR (Security Orchestration, Automation, and Response) would improve your security, but it's more oriented to the automation of an existing Incident Response plan. If you're thinking of implement a SOAR you're to likely already have a SOC (Security Operations Center), which it is, in a way, IT Staff.