A Comprehensive Risk Management Framework for Approaching the Return on Security Investment (ROSI)
Elvis Pontes, E. Adilson, Anderson Silva, Sergio T. · InTech eBooks · 2011
For designing cost-effective security strategies, organizations need practical and complete frameworks for security and risk management (RM), with methods for measuring and managing risks within organizations. In the recent years computer systems have become more present in all economic fields, improving activities in the industry, commerce, government, and researching areas. For the near future the same growing rate of cyber technology is projected for all those areas (Federal Information Security Management Act [FISMA], 2002). On the other hand, threats for this new way of doing business are also growing significantly: hackers, computer viruses, cyber-terrorists are making headlines daily (Internet Crime Complaint Center [IC3], 2008). Consequently, security has also become priority in all aspects of life, including business supported by computer systems (Sonnenreich et al, 2006). In this reasoning line, some major points may worry researchers, technology implementers, decision makers and investors: 1) the framework to be adopted in organizations for making business secure; 2) managing security and risk levels in organizations for making business workable; 3) mainly, the return of security investment has to be measured to make business profitable. For business, when the topic is security, it is hard not to consider the associated financial aspect, as any other costs (time, processing, electric power, throughput, etc.) (Pontes et al, 2009a, 2009b, 2009c, 2010). However, for the decision makers it does not matter whether firewalls or soldiers are going to protect the Enterprise Resource Planning (ERP) system and/or other servers. Instead, decision makers have to be aware of the costs related to security and the consequences on the bottom line, both for the present day and for the time yet to come (Sonnenreich et al, 2006). So, it is important that Information Technologic (IT) and Information Security (IS) professionals to be aware about how to justify costs and investments in IS (National Institute of Standards and Technology [NIST] SP800-65, 2005), (International Standardization Organization, [ISO] TR 13569, 2005). Besides, all the related security costs must be correctly presented faced to the real necessities. Risk Management (RM) and Risk Analysis (RA) are efficient means for both: to show the needs of protection and the impact in the overall business activity (ISO 13335, 2004), (ISO 27005, 2008). Usually employed together with RM, the Cost-Benefit Analysis (CBA) may identify the costeffectiveness for the security countermeasures, supporting the statements of the IT or IS