Why ROI and similar financial tools are not advisable for evaluating the merits of security projects

Charles Cresson Wood, Donn B. Parker · Computer Fraud & Security · 2004

Abstract During the last 30 years, the period in which information security has become a widespread concern, many people have attempted to evaluate information security projects with traditional financial analysis tools (ROI, NPV, IRR, Payback, etc.). The results have been unsatisfying because information security does not lend itself to the same type of analysis, as for example could be readily performed on the upgrade of a server used for production processing. In this article, we discuss some of the reasons why this is the case, as well as several other evaluation methods that can instead be used to make justifiable and relevant decisions about information projects.

Read the paper · More papers on PaperTik