This is cache of http://feeds.feedburner.com/~r/bloginfosec/krfr/~3/222230899/. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
Intel ROSI Paper: Sets Practical Guidelines and Proper Expectations
2008-01-24 11:00:35 by Kenneth F. Belva in BlogInfoSec.com
 

Late last year I read Matthew Rosenquist’s paper, Measuring the Return on IT Security Investments, over at Intel. I’m glad I have a few minutes to write about it.

The premise for the paper is simple: the implementation of a security measure (control) should result in a decrease in the number of security incidents for a given environment. Therefore, by quantifying these incidents over time — before and continually after the security control is implemented — we will produce a metric that will demonstrate the effectiveness and return on an information security investment.

I enjoyed the paper because it’s pragmatic and it properly set my expectations:

  1. It will not work in every environment: the bigger the environment, the better
  2. It uses quantitative metrics
  3. It does not strictly define a security incident, that’s left to the individuals using the metric
  4. It’s generally simple to follow and explain to non-security management
  5. It does not contain marketing fluff

A paper such as this helps to explain why operations and security are very closely aligned: a decrease in security incidents will also be a decrease in operational costs.

It’s also a very practical counter to the non-ROSI / non-ROI arguments that seem to crop-up from time to time.

Here’s a link to Matt on video discussing Intel’s Security ROSI.


Copyright © 2008 BlogInfoSec.com. This feed is copyrighted by bloginfosec.com. The feed may be syndicated only with our permission. If you feel that this feed is being syndicated by a website other than through us or one of our partners, please contact bloginfosec.com immediately at copyright()bloginfosec.com. Thank you! Again, please contact copyright@bloginfosec.com so we can take legal action immediately.

 
 
 
 
 
 
TOP SEARCH
Expand / MinimizeClose Widget
  •  
RECENT SEARCH
Expand / Minimize
  •  
RELATED VIDEO
Expand / Minimize
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia