|
|
Action
|
Cost
|
Security Impact
|
|
Dedicate one staff member to maintaining security systems.
|
$
|
****
|
|
Educate staff and promote awareness.
|
$
|
****
|
|
Schedule regular virus and patch upgrades, firewall reconfiguration, PC security audits, etc.
|
$$
|
***
|
|
Hire or reassign staff to create and enforce security polocies.
|
$$
|
***
|
Install basic hardware and software: firewalls, antivirus software, passwords, etc.
|
$$$
|
**
|
|
Buy advanced hardware and software, such as encryption, token authentication, digital certificates and signatures.
|
$$$
|
***
|
|
Outsource your worries.
|
$$$$
|
****
|
|
Hire or train programmers to write security code.
|
$$$$
|
***
|
|
Conduct regular security and penetration audits or assessments.
|
$$$$
|
***
|
Information Security ROI
Need hard data justify your security spending? Researchers are turning up quantifiable evidence of the return on security investments (ROSI).7
A team from MIT, Stanford and @Stake, a Massachusetts-based security consulting firm, has demonstrated that the earlier developers code security into their software, the higher the ROI. Building security into the design stage nets a 21% ROSI.
A company that expects to lose $100,000 annually due to network intrusions will experience a ROSI of $45,000 if it purchases a $40,000 IDS system that's 85% effective, according to a formula developed by researchers at the University of Idaho.
Carnegie Mellon has shown that higher information security spending helps minimize the damage from an attack.
|
|
|
|
|
|
|
|
 |