Valuing Information Assets for Security Risk Management
Ralph Spencer Poore · Information Systems Security · 2000
Information security professionals are often asked by management to balance the cost of controls against the value of the information assets that the controls protect. Valuing information for this purpose differs significantly from valuing information for accounting purposes. In most cases, the organization is not trying to sell its data to others and has not established a marketplace in which the data's value could be tested. Cost-based valuations (often used to determine a “book” value for intellectual property) also fall short for risk management purposes. Nonetheless, relying on opinion averaging or similar highly subjective techniques rarely results in defensible valuations. This article explores the reasons for valuation in a security risk management context. From these reasons, it is possible to discover effective and defensible techniques of both a quantitative and a qualitative nature.