Evaluation of biometric implementers to investigate a viable return on security investment technique
R. C. Skinner, P. J. Duparcq, Stephen J. Elliott, Melissa Jane Dark · Annual Information Security Symposium · 2004
Within an enterprise-level organization's IT system, ultimately upper-level management approves of new investments and technologies that are to be deployed or tested. One of the key factors that management takes into account is what the overall effect is on the bottom line, or the return on investment. There are various techniques that organizations use to determine this factor; however the process has not been standardized. The term ROSI (Return on Security Investment) was developed a couple of years ago, with exceptional contributions from University of Idaho (using Network Intrusion Detection Systems) and Stanford, MIT, @Stake (developing Secure Software Engineering). The term did strike interest within a variety of different sources. However, the solution of an ample return on security investment is still being asked today. There are multiple technologies that allow an organization to secure their IT system. Biometric security is one of the technologies however; it has been a hard technology to adopt based upon a variety of factors including cost to implement, lack of standards, and lack of large scale published deployments. According to Ernst and Young's 2003 Global Information Security Survey that had responses from over 1,400 organizations, nearly 60% or organizations say they rarely or never calculate ROI for information security spending.