Buying and budgeting · 1.3

What to build and what to buy

What to build and what to buy. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see BleepingComputer security news.

The question

Build what is yours, buy what is everybody's

The controls in the standard divide reasonably cleanly. Some describe your business and nobody can supply them. Some are the same in every organisation and building them is reinventing a commodity.

Buy

Where buying is almost always right

Identity and access management. Logging and retention. Endpoint protection. Vulnerability scanning. Encryption at rest and in transit. Backup.

Each is a solved problem with mature products, each requires continuous maintenance that a small team cannot sustain, and each is something an assessor has seen a hundred times and knows what good looks like.

Building any of them means becoming a security product company alongside being a manufacturer, and the second job does not stop.

Build

Where building is the only option

The system security plan. The boundary definition. The procedures describing how your people actually work. The record of decisions and why they were taken.

These are descriptions of your organisation. A template is a starting point and a plan that is visibly a template is a finding: assessors read a great many of them and can tell.

The middle

Where it genuinely depends

Anything touching the shop floor. The equipment is specific, the processes are specific, and the products in this space are younger than the products in the categories above.

The test is whether your situation is unusual. If your machines, your file routes and your constraints look like other suppliers', buy. If they do not, a product will need so much adaptation that you are building anyway, with less control.

The hidden cost of building

Maintenance, and the person who leaves

Something built in-house is maintained in-house, indefinitely, by somebody. When that somebody leaves, the maintenance becomes an archaeology project, and the assessor's question about how a control works receives an uncertain answer.

Ask, before building anything: who maintains this in three years, and what happens if they resign. If the answer is one named person and a shrug, buy.

The hidden cost of buying

Configuration is where the work went

A purchased product satisfies a control when configured correctly and evidenced. Neither is included, both take longer than the deployment, and the deployment is what the vendor timeline describes.

Budget the configuration and the evidence separately from the licence, or the year-one figure will be wrong by a wide margin.

A rule of thumb

If an assessor has an opinion about it, buy it

Where a control is common enough that assessors have expectations about how it is satisfied, meeting those expectations with a recognised product is faster and cheaper than defending an original approach, however good the original approach is.

Save the originality for the parts of your environment that are genuinely unusual, which on a shop floor is most of them.

The half-built case

The worst outcome is a half-built tool

Something started in-house, working for the demonstration, never finished, and now load-bearing. It appears in the plan as a control and in reality as a script on somebody's machine.

Assessors find these by asking how a control works and listening for hesitation. If you have one, either finish it properly or replace it, and do that before the assessment rather than during it.

A short test

Three questions before building anything

Does this describe our business, or would it be the same at any supplier? Who maintains it in three years? And would an assessor recognise the approach?

Two answers pointing at buy is enough.

Documentation is always build

The exception that has no exception

Every supplier writes their own plan. Products generate templates and a template that has not been made specific is visible immediately, both to an assessor and to anybody in the business asked to follow it.

Budget the writing as writing: somebody's weeks, not a licence.

Open source

The middle option that is really building

Open components can satisfy several of the commodity controls at low licence cost, and they carry the maintenance burden of something built in-house. Treat the decision as a build decision and apply the same three questions.

Reversibility

Prefer the option you can undo

Buying can be reversed with notice and an export. Building can be reversed only by building something else. Where the two are close, the reversible one is worth a premium, particularly early, when you know least about your own requirements.

Two years on

Revisit the decision once

A build that made sense when nothing suitable existed may not once the market has moved, and products in the shop-floor category are changing quickly. Put a reminder two years out to ask the three questions again.

The answer is often the same and the review costs an hour.

The register

Write down which way each decision went

A one-line record per control: bought, built, or manual, and why. It takes minutes, it answers the assessor's question about how a control is satisfied, and it prevents the same argument being had twice in eighteen months.

Skills you already have

A manufacturer knows how to buy capital equipment

The build-or-buy question is one your business answers routinely about machines: total cost over the life, who maintains it, what happens when the supplier disappears, and whether the bespoke option is worth the dependency.

Apply the same reasoning here. The subject is unfamiliar and the decision is not.

Also

Elsewhere in buying and budgeting