Вы находитесь на странице: 1из 14

 

 
Universal Best Practices for Managed 
Services 
By Charles R. Weaver J.D., in association with Nimsoft 

   

1
Table of Contents 

Introduction ...................................................................................................................................... 3

Ethics.................................................................................................................................................. 3

Impartiality ........................................................................................................................................ 4

Understanding the Law & Regulation.......................................................................................... 4

Confidentiality.................................................................................................................................. 5

Disclosure .......................................................................................................................................... 6

Managed Services Expertise ......................................................................................................... 6

Process, Process, Process ............................................................................................................... 7

Bring the Right Tools ........................................................................................................................ 8

Security.............................................................................................................................................. 9

Continuing Education...................................................................................................................10

Protect Your Profession .................................................................................................................10

Managed Services Accreditation Program .............................................................................11

Conclusion......................................................................................................................................12

2
deep relationship they have with their
clients. MSPs enjoy the trust of their
Introduction  clients in a way that few other IT
The managed services profession is as management companies ever realize.
complex as it is diverse and continues to When a client decides to use a MSP,
change to meet the needs of its many they don’t’ just agree to pay money
clients throughout the world. Yet, with all every month. Managed services clients
these changes facing the managed provide their MSPs with access to some
services industry there have been a very sensitive information. Access to
core group of principles that have corporate networks and systems,
successfully guided MSPs throughout the employee and customer data, are just
years. These “best practices” are simply a few of the precious assets clients give
philosophies that successful MSPs have over to their MSP. This level of trust
used; in fact, most of these practices should never be taken for granted.
are considered to be fundamental to
running a successful business in many MSPs have an obligation to behave in
other industries. an ethical manner. Technical
proficiency is not enough to a
These best practices can be employed managed service provider. MSPs must
by MSPs of all shapes, sizes, and vertical use their technical expertise in a way
markets. In addition to being good that always puts the client first. Having
business principles, these best practices the appropriate ethical foundation is
will allow MSPs to become highly important as it will serve as the template
profitable, efficient, and scalable. While for everything you do as a MSP.
there are undoubtedly other
philosophies that are worthy of mention MSPs must be responsible for what their
in the managed services profession, employees do, just like attorneys and
these specific best practices were doctors. In fact, almost every profession
chosen because of their universal in existence has both a
application and importance for MSPs technical/educational requirement as
everywhere. well as a requirement that the
professional behave in an ethical
manner while performing their official
Ethics  duties. If MSPs want to ensure the
MSPs are different from any other type longevity of their profession adhering to
of IT service provider. What makes them a strong ethical foundation is crucial.
unique is not their remote monitoring
Managed Service Provider’s Code of
and management technologies or their
Ethics & Conduct
recurring revenue model, but rather the
3
Impartiality  Understanding the Law & 
MSPs have the trust of their clients and Regulation 
that trust should never be compromised.
As the intersection between law and IT
One of the characteristics that
becomes more defined MSPs are being
distinguish a MSP from other IT providers
asked to know more about legal issues
is their ability to render impartial advice
that impact their clients. Now, it is
and counsel. The ability to elevate the
important to know when you have gone
client’s interests above those of the MSP
too far and are actually practicing law
is not only a key element of a successful
without a license. This is something you
MSP it is also a key element of many
should not do. However, as a MSP it is
other venerated professions.
imperative that you understand the
While other IT providers tend to be basic legal issues and regulations that
motivated by other interests, a MSP will are likely to affect your clients.
evaluate the situation and then
For example, today there are many laws
proscribe a course of action that is
dealing with data breaches and what a
rooted solely in furthering the client’s
company must do when they have
best interests. It may seem contrary to
suffered a data breach. It is important
what they are accustomed to but MSPs
for MSPs to be able to advise their
should avoid conflicts of interest at all
clients on how to protect their networks
costs. MSPs have a lot of important
from such loss of data. Furthermore, a
relationships with third parties that are
good MSP will also know when to advise
necessary for them to do their jobs.
their clients to seek representation from
However, these relationships should
an attorney when appropriate. Another
never compromise the MSP’s obligation
common issue facing many companies
to the client. Vendors, other MSPs,
today is data storage and archiving. In
consultants, and other parties can tend
many jurisdictions, not just in the United
to insert themselves into the MSP/client
States, there are laws mandating how
relationship. While these relationships
certain data must be stored. Certain
are necessary, a MSP must always
vertical markets, like financial services,
remember their primary obligation to
face additional pressure by having
the client and never let that obligation
specific regulations that require data
be swayed or compromised.
(like email and instant messages) to be
Always render advice that benefits your archived for a certain amount of time so
clients, not your own interests. This is the it can be readily accessed at any given
job of the MSP. moment. MSPs need to be aware of
these regulations.

There are likely many other scenarios


where MSPs will be asked by their clients

4
to render advice on situations that being written that will have an impact
involve a greater legal issue. In the on how company’s run their IT. It is no
future, MSPs and legal professionals will longer acceptable for MSPs to be
be required to work in concert to ignorant of how laws and regulations
resolve client issues that are both affect their clients. In order to be an
technical and legal in nature. MSPs will effective MSP, you must have a minimal
be well served to be aware of legal knowledge of legal issues and how they
cases and regulations as they emerge will impact your clients.
since these issues will in all likelihood
impact at least some portion of the
client’s IT environment. Confidentiality 
MSPs have access to a lot of sensitive
There are many good places to learn information. Some of this information is
about laws that are impacting IT. A freely given by the client. Clients often
good place to start is to read non-IT will trust their MSP to help with important
publications as these will be more likely projects and long term goals. It is
to report on a legal story. Another good therefore necessary to divulge certain
paper that describes many legal issues information to MSPs in order for them to
that impact MSPs is “A Legal Guide to do their job. Naturally, clients trust their
Managed Services” by Robert J. Scott of MSPs with this important information
Scott & Scott LLP. Because there are because they expect them to keep it
many areas where IT and the law are confidential. Many service level
just now beginning to intersect it may be agreements fail to mention
difficult for MSPs to get much confidentiality between the MSP and
information from the mainstream or the client. While the contents of any SLA
even IT press. As a result, it is up to MSPs should ultimately be up to the client and
to discuss these scenarios amongst the MSP to discuss, MSPs should operate
themselves in order to better under a general assumption that any
understand what their industry response information entrusted to them during
should be. Even though this is an the course of their representation of a
emerging area of legal philosophy, client will be kept confidential.
MSPs are right in the middle of this
evolution and must be aware that they Just as there are confidentiality rules for
will be impacted one way or the other. physicians and attorneys, so are there
Therefore, it is better that MSPs begin to rules for MSPs. The trust that exists
look outside their own industry and between MSP and client forms the basis
realize that they are part of a larger of the relationship. Without this trust
universe. there could be no way for the MSP to
do their job. MSPs need their clients to
IT and the law now share a common trust them with information in order to
present and future. Today there are laws recommend solutions and provide
5
advice. Of course, there are exceptions with tests of their abilities and resources.
to any rule. It is natural for clients or partners to
make requests of MSPs that push the
Under certain circumstances MSPs can boundaries of their capabilities. As such,
be compelled to divulge information
it is up to the MSP to know when their
that has been entrusted to them by a capabilities are being pushed too far.
client. For example, if asked to testify in
When this happens, the MSP must
a court of law (or if otherwise compelled disclose to the client anything that
by a legitimate governmental authority)
would otherwise mislead the client.
a MSP would be expected to respond in
a truthful manner. In the absence of any For example, if a client asks a MSP to
legitimate authority, MSPs should work on a particular technology and
consider their duty of confidentiality to the MSP has absolutely no experience in
their client to be supreme. that area they should disclose this fact
to the client. In other cases, the MSP
may have a pre-existing relationship
Disclosure  with another company that would
When we go to a doctor or a lawyer preclude the MSP from doing business
(and some other professionals) there is a with the client. A more likely a scenario
process whereby the professional will is when a MSP, in the normal course of
interview the prospective client/patient. the sales cycle, omits certain facts that
This interview process is performed for a would otherwise cause the client to
few reasons. One reason is many change their opinion about the MSP. By
professionals like to understand the omitting important facts MSPs can
nature of the case prior to taking improperly influence the client. By
something on for which they are always maintaining an open and honest
unprepared or unqualified. Another level of communication with the client
reason for conducting a pre-interview is MSPs will help earn and preserve the
to identify any conflicts of interest that trust placed in them.
might prevent the professional from
taking on the new client.
Managed Services Expertise 
Disclosure is a key component of a
When you go to a professional (whether
professional’s obligation to a client.
it is a doctor, lawyer, accountant,
Disclosure might come in the form of the
engineer, etc.) you expect certain
MSP telling a client that they cannot
things. For instance, you expect that
represent them due to a pre-existing
professional to be “technically”
relationship with another company. The
proficient in what they do. If it is a
MSP might tell the client that they are
doctor, you expect that doctor to
not qualified, for whatever reason, to
understand the basics of practicing
take the job. MSPs are always faced
medicine. You do not go to a
6
physician’s office and ask the doctor to expecting them to tell you that they
prove their knowledge of medicine. It is cannot perform the task required. In
assumed that the medical degree such a situation you could expect the
hanging on the wall (along with the fact MSP to make a referral to another MSP,
that it is illegal to practice medicine or at least hear them explain that they
without a license) proves that this do not have experience in doing such a
person has had medical training and is thing but that they can either partner
qualified to practice medicine. This is with someone else to do it or they can
equally true with many other learn how. It goes without saying that to
professions. misrepresent your abilities as a MSP
would constitute a fundamental breach
Furthermore, it is expected that a of the Managed Service Provider’s
professional (let’s keep using the
Code of Ethics.
example of the doctor) will be able to
identify situations where they are not As a MSP it is up to you to maintain the
qualified and make the appropriate standards set and adhered to by other
recommendations. It is often the case MSPs. Understanding when it is
where a doctor will identify a patient acceptable to take on a client and
that has a medical condition that when you should make a referral or
requires expertise beyond what the simply say no is an important part of
doctor can offer. In these situations, it is your role as a managed services
quite common to make a referral to professional.
another physician. It is essential that
professionals demonstrate a minimal
amount of expertise to practice their Process, Process, Process 
trade and yet know when they are MSPs utilize many different tools and
being asked to render advice that is resources in order to deliver their
beyond their current level of services to a client. There are many
understanding. This is no different with different types of tools available to MSPs
MSPs. today; technology, business, financial,
sales/marketing, even legal tools are
It is assumed that a MSP has a basic necessary components in the MSP tool
level of technical knowledge. Think of bag. There is one critical component
how silly it would be to have to contact that is used by all effective MSPs and it is
a MSP and make them prove that they the one resource that cannot be
are technically competent to manage purchased: I am talking about a
your IT. Certain things must be assumed managed service delivery process.
if only for ease. However, if you contact
a MSP and you ask them to do No matter how many fancy gadgets
something that is beyond their level of and technologies you possess, without
expertise, you would also be correct in the right service delivery process in

7
place you will find it very difficult to be a For more information about the IT
profitable or good MSP. Some processes mentioned please visit the
companies believe that if you buy a following sites:
remote monitoring or management
http://www.iso.org/
product you will automatically be a
MSP. This is like saying if you buy a http://www.motorola.com/motorolauni
scalpel you are a surgeon. Of course, versity.jsp
this is not the case. Without the right
knowledge no tool in the world will help http://www.itil-officialsite.com/
raise you to the level of a professional
http://www.isaca.org/cobit/
MSP.

There are many different IT service


delivery processes available today. ITIL, Bring the Right Tools 
ISO, Six Sigma, and CoBIT, are just a few. Once you have developed your service
You can even create your own service delivery process the task of choosing
process. What is important is you which tools you will need becomes
document your processes and subject it much easier. Far too many MSPs go out
to periodic review and change. As a and buy a set of managed services
MSP, your process is what makes you tools without ever knowing what type of
unique. While every surgeon uses the practice they will have. Different MSPs
same (or similar) tools, it is their need different tools. You must know
experience and knowledge that makes what type of services you will be offering
them unique from their colleagues. before you can buy the tools.
Having a process for delivering your
When a young MSP goes out to
managed services will also help you in
purchase an IT product, if they
other areas of your managed services
understand that technology will be used
practice. A process will help you
they will be able to better evaluate and
become more efficient, it will identify
acquire technologies that are relevant
areas of your practice that need to be
to their managed services practice. For
made more secure, it will even help you
example, if a MSP has predominately
make more money (think of all the
smaller clients, then going out and
wasted time your technicians spend
buying the most expensive IT
because they do not have any
management tools might not be the
guidance when it comes to how your
smartest approach. On the other hand,
managed services are delivered). For
if you have very large clients (or clients
the minimal amount of time it takes to
that demand sophisticated managed
develop your own process, you will reap
services) then buying the cheapest tool
numerous benefits for your managed
with minimal service delivery features
services practice.
may not be wise. Similarly, if you are

8
providing a lot of security services to assets of their clients. It is expected that
your clients, then having a tool set that is MSPs will take certain precautions to
feature rich on security would be a safeguard client data and
necessity in any product suite you infrastructure. For example, just as other
purchase. professionals are responsible for the
actions of those employees who work in
Having the right tools is one of the key
their office, so are MSPs responsible for
benefits of using a MSP. If clients could technicians who touch or interact with
have easy access to IT management
clients. Having a detailed and
tools and knew how to use them, the documented internal security policy is
value of a MSP would be greatly
very important for MSPs. Not only will it
diminished. Fortunately for the MSPs, help the MSP maintain the appropriate
there are a lot of different tools out
level of internal security, it will also go a
there and using any one of them can long way in showing the client that the
be quite tricky. IT managers typically do
MSP takes security seriously.
not want to have to deal with keeping
up this type of technology; instead, they Some of the following items may help
want to maintain a focus on their you begin to think about what security
company’s IT. Leveraging an protocols you should have in your
experienced MSP with the right tools managed services practice:
can help many companies (including
- Documented security practices
their IT staff) maintain an effective hold
on their IT management. - Human Resource safeguards (i.e.,
background checks, appropriate
corporate computer use, etc.)
Security  
It is expected of professionals that they - Strong authentication
will practice what they preach. If a
- Unique User IDs
doctor tells you that it is unsanitary to
not wash your hands, you would expect - Encryption of data, particularly
that same doctor to also wash their data that is stored
hands prior to seeing patients. MSPs
frequently tell their clients to treat data There are many other security measures
in a secure fashion lest it fall into the you can implement; including
wrong hands. It is only natural to expect technologies you can employ to help
your MSP to abide by certain security you safeguard your practice. Whichever
practices to prevent client data from path you take, make sure you at least
becoming compromised. consider all the ways you need to
protect yourself, both from internal and
MSPs, as we have already discussed, external threats. If you protect yourself it
have a lot of responsibility for the IT is a lot easier to protect your clients.
9
Continuing Education  for social networking, it is about keeping
in touch with a professional community
MSPs are responsible for a lot of things.
so you do not fall behind.
To simply say a MSP manages the IT for
their clients is an understatement. MSPs Another important reason for
have to be vigilant on many fronts in participating in the ongoing education
order to do their jobs. As such, of your profession are so younger
education becomes a major role in members will quickly adopt the same
keeping MSPs aware of what is standards and practices. Imagine if
happening in the world and how it every new doctor decided to do things
impacts their clients. their own way and completely
disregarded proven medical standards.
Other professions encourage their
A lot of patients would be needlessly
members to continue their education of
harmed. In addition, the medical
the trade, even after their formal
profession would quickly fall into
education is complete. Both doctors
disrepute if there were no standards to
and lawyers have continuing education
be enforced.
even after they have graduated from
their respective schools and received As MSPs, it is incumbent upon you to
their degrees. In fact, both of these safeguard your profession by educating
professions make continuing education and guiding younger MSPs. To let these
a requirement. Doctors and attorneys, new entrants fall outside the normal
among other professions, make their practice guidelines would not only harm
members constantly aware of all the clients, it would also jeopardize the
advancements and changes in their legitimacy MSPs currently enjoy in the
profession. Whether it is technology, market.
changes in case law, or simply being
aware of trends that will impact the
profession, all mature professions have a Protect Your Profession 
requirement to remain educated. Every profession experiences attacks on
the credibility and legitimacy of their
MSPs deal with technology on a daily
trade. Whether it is a doctor that harms
basis. Perhaps no other profession is as
a patient, a lawyer that harms his
quick paced as IT management. Threats
client’s interests, or an accountant who
can emerge on a daily basis and if the
loses his client’s money, there will always
MSP is unaware of these changes it can
be instances where the managed
negatively impact their clients.
services profession will be tested. Many
Moreover, MSPs need contact with
of the theories discussed in this paper
other MSPs in order to maintain a sense
speak directly to the preservation of
of community, if only to hear about how
MSPs and the important work they
other colleagues are dealing with similar
perform.
issues. This educational process is not just
10
MSPs should be a little protectionist actual governmental interference in the
when it comes to their profession. This is future. Every other profession has
only natural. Setting and enforcing regulated itself to prevent official
standards for other MSPs is an effective governmental regulation. Even if some
method for preserving high quality levels official government agency attempts to
and maintaining consumer credibility in regulate the managed services
the managed services community. profession the existence of some form of
When companies were value added self regulation will help the MSPs create
resellers, this sense of community did not a regulatory environment that is more
exist. As such, nobody paid attention to favorable to them. No other group will
the consumer and whether or not their pay attention to standards in managed
interests were being protected. As MSPs, services if the MSPs do not do it
companies can no longer remain themselves.
isolationist in their behavior. Instead,
MSPs should embrace this new sense of
community and rejoice in their new Managed Services Accreditation 
found ability to learn, grow, and prosper Program 
in the managed services profession. There are many certifications that
It is imperative that MSPs work to self should be examined by MSPs. The
regulate their industry before it is done natural starting place is to become
for them by some outside group. The certified on the technologies you
technological advancements and currently use. If you are Microsoft
overall business progress the IT sector partner and also sell a lot of SonicWALL
has shown over the last several decades you may want to consider obtaining
is one of the main reasons this industry any certifications provided by those
has not yet been regulated by vendors. As was discussed elsewhere in
governmental bodies. However, it is a this paper, it is assumed that MSPs have
foregone conclusion that some MSPs will technical competency in the areas in
be accused, whether fairly or unfairly, of which they practice. It would be wise to
harming the welfare of the general seek certification in as many of the
public. When this happens it will be a products and technologies you support
natural reaction by the general public, as a MSP. This will keep you up to date
and soon thereafter politicians, to on any changes to the technology and
safeguard the mass public by some it will provide your clients with additional
form of direct or indirect regulation. security and comfort.
MSPs would be well advised to take this In addition to technical product
eventuality seriously and begin to certifications, if your company has even
exercise some semblance of self- a small percentage of revenues from
regulation and enforcement of managed services you should plan on
standards as a means of preventing
11
taking the Managed Services Conclusion 
Accreditation Program™ exam
The managed services profession is
(MSAP).The MSAP exam is the only
growing at a rapid pace and will likely
neutral benchmark of a company’s
continue at this speed for the next
ability to safely and efficiently deliver
several years. This growth will largely be
managed services to end-users. What
driven by a combination of increased
makes the MSAP exam so unique is that
regulatory pressure as well as the
it was created by MSPs who wanted to
mounting complexity of even basic IT
have a vendor neutral standard of
management. Businesses need
excellence for other MSPs to follow.
Managed Service Providers. This will
Not only is the MSAP exam well likely never change. More importantly,
respected by many governmental and businesses need to be able to place
financial institutions (like Lloyd’s of their trust in a professional body of MSPs
London and AIG) it has also been and know that their IT management
successfully used by many MSPs when needs will be looked after and not
undergoing rigorous scrutiny by a abused.
prospective client. Client’s like to see
If you would like to read more about the
standards like the MSAP because it gives
Managed Services profession there are
them greater comfort in knowing their
many books available. In particular,
MSP will be held to a high standard of
“The Art of Managed Services” provides
excellence.
a very good overview of the managed
Finally, taking the MSAP exam is a great services marketplace as well as helpful
way to identify areas where your tips for improving your overall managed
managed services practice could be services practice.
improved. Similar to how we learn in
MSPs have an incredible amount to be
grammar school or college, the MSAP
thankful for these days. The continued
exam will force you to rethink your
collision of law and technology is
business and technical strategies,
forcing even the smallest of
thereby helping you to find areas where
organizations to take their IT seriously.
you are performing at a less than
Remember, these best practices are
optimal level.
part of a larger framework of guidelines
For more information on how to take the and standards for MSPs. It is up to you,
Managed Services Accreditation as a MSP, to diligently strive for
Program™ exam please contact the perfection as you manage and
MSPAlliance at info@mspalliance.com safeguard the IT assets of your clients. If
you adopt these best practices and put
them to use, you will go a long way in
securing and improving your managed
services delivery. By adopting these best
12
practices you will not only be building a
successful and more profitable
managed services practice for your
own company but you will also be
taking the necessary steps to protect
this profession for many years to come.

13
About MSPAlliance

The MSPAlliance is a global organization made up of service providers and technology


enablers who work in a collaborative effort to define, promote and educate the
Managed Services Industry and the end-user consumer on the adoption and successful
use of technology through Managed Services. The MSPAlliance works as a vendor-
neutral body to promote the Managed Services Industry and its members, as well
as serve as an accrediting body. The MSPAlliance harnesses the expertise and support
of the MSPAlliance Advisory Board and MSPAlliance Industry Outreach Council. With
thousands of corporate members world-wide and growing rapidly, the MSPAlliance is
an unparalleled powerhouse, and the ONLY unified voice for the Managed Services
Industry!

About Nimsoft

Nimsoft provides next generation performance and availability monitoring solutions for
the complete physical and virtualized IT infrastructure. The Nimsoft solutions redefine the
standards for ease of use and speed of deployment - providing outstanding return on
investment and unparalleled customer satisfaction. Over 600 customers in 30 countries
rely on Nimsoft solutions to monitor their IT based business applications and services.
These customers include mid-market and global organizations, such as Barclays Capital
and Amway Corporation, Bay Area Rapid Transit, Ladbrokes, TRW Automotive, and
hundreds of leading managed service providers such as CDW Berbee, Easynet,
FusionStorm, Rackspace Managed Hosting, and T-Systems. For more information, visit
www.nimsoft.com.

14

Вам также может понравиться