home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security Watch
C O L U M N  
Desperately Seeking the Security ROI

  May 27, 2002
  By Greg Shipley

TOC Issue TOC
Printer Print full article
E-Mail E-Mail this URL

If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. --White House cybersecurity adviser Richard Clarke



If we measure a particular cause's success by how high up the food chain pleas for it go, it's apparent that information security has gained some serious ground. Two years ago, security practitioners considered themselves lucky to even have the word security in their titles, and now we've got White House aides and CEOs from industry behemoths such as Cisco and Microsoft proclaiming security as core to their efforts.

Talk may be cheap, but the infosec price tag is not. It shouldn't come as a surprise that the infamous TCO (total cost of ownership) and ROI (return on investment) justifications have descended upon the unsuspecting troopers in the infosec trenches. Apparently, it's time for us security geeks to learn some new tricks.

Like many people active in the security community, I spend a good portion of my spare time frequenting a select group of public mailing lists. One of my longtime favorites is the SecurityFocus IDS list, primarily because my intrusion-detection coverage for Network Computing has left me with an unquenchable thirst for knowledge and because of the high caliber of contributing list members. Amid all the normal mailing-list noise is some truly insightful dialogue. For example, shortly after a debate on NIDS (network-based intrusion-detection system) testing erupted, a completely nontechnical question burst into our inboxes: What's the ROI on an IDS solution? You expect to hear about packet normalization and application evasion techniques on an IDS list, but ROI discussions? Certainly not.

The thread brought about interesting comments, good pointers to articles and a few proposed formulas for calculating potential ROI values for an IDS deployment.

One proposal suggested calculating the annualized loss expectancy (ALE) using asset values, the percentage of loss expected per incident, and the total number of estimated incidents. By determining the ALE, you could compare it to the costs of maintaining the IDS solution (essentially, IDS' TCO), which could then be used to calculate the technology's ROI. A team from the University of Idaho submitted a paper in which it proposed factoring in annual costs from an estimated number of intrusions. (Users wishing to investigate the actual equations can read the thread.)

Obviously, people put a great deal of thought behind many of these ROI proposals, but it's difficult to "plug and chug" with these formulas because there are too many unknowns. For example, most organizations are unable to quantify -- fiscally -- their digital assets. Many organizations are unaware of how many actual security incidents they have faced, nor have they tracked how much those incidents have cost.

These first-run ROI models may leave some organizations with more questions than answers. But that's not necessarily a bad thing. Organizations must start answering some basic questions, primarily, what do I have and how much is it worth to me? Asset identification, as trite as it may sound, is still a cornerstone. By gathering answers to some of the basics, organizations can begin to understand the true security risks and, in turn, potential returns on security investments.

As security spending increases, so will the need to represent issues more traditionally. Refined ROI formulas and methodologies are sorely needed. Larger data sets are sorely needed. There's a long road ahead of us, but the closer we come to tangible numbers, the closer we come to answering the really important questions, like how does our beverage budget compare to our security budget?

Send your comments on this column to Greg Shipley at gshipley@neohapsis.com.







Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights