4.1.1. Information Security Resources
💡 First Principle: A security program's resourcing model has to be justified by the gap it closes, the same way any other business investment is — headcount and tooling added without a documented target don't compound into maturity, they just accumulate.
Resourcing decisions span people (in-house staff versus managed security service providers, and the skills mix between them), budget (both capital investment in tools and ongoing operational cost), and tooling (an inventory of what's already owned, so new purchases don't duplicate existing capability). A resource gap analysis — comparing current staffing and tooling against what the strategy and risk register actually require — is what turns a resourcing request into a defensible business case rather than an assumption that more is automatically better.
| Resource Type | In-House | Managed Service Provider |
|---|---|---|
| 24/7 monitoring | High fixed staffing cost | Variable cost, faster to stand up |
| Deep institutional context | Strong | Weaker — needs onboarding |
| Specialized skill (e.g. forensics) | Expensive to retain | Available on demand |
| Long-term capability building | Builds internal expertise | Expertise stays with the provider |
⚠️ Exam Trap: A scenario describing a security team that has grown significantly in headcount, with no corresponding improvement in program maturity, tests whether you recognize that resources without a structured roadmap don't produce results. The correct answer points back to gap analysis and prioritization, not simply "hire more people."
Reflection Question: Your security team has tripled in size over two years, but audit findings from three years ago remain unresolved. What does this suggest about how resourcing decisions have been made?