home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security Watch
C O L U M N  
Desperately Seeking the Security ROI

  May 27, 2002
  By Greg Shipley

TOC Issue TOC
Printer Print full article
E-Mail E-Mail this URL

If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. --White House cybersecurity adviser Richard Clarke



If we measure a particular cause's success by how high up the food chain pleas for it go, it's apparent that information security has gained some serious ground. Two years ago, security practitioners considered themselves lucky to even have the word security in their titles, and now we've got White House aides and CEOs from industry behemoths such as Cisco and Microsoft proclaiming security as core to their efforts.

Talk may be cheap, but the infosec price tag is not. It shouldn't come as a surprise that the infamous TCO (total cost of ownership) and ROI (return on investment) justifications have descended upon the unsuspecting troopers in the infosec trenches. Apparently, it's time for us security geeks to learn some new tricks.

Like many people active in the security community, I spend a good portion of my spare time frequenting a select group of public mailing lists. One of my longtime favorites is the SecurityFocus IDS list, primarily because my intrusion-detection coverage for Network Computing has left me with an unquenchable thirst for knowledge and because of the high caliber of contributing list members. Amid all the normal mailing-list noise is some truly insightful dialogue. For example, shortly after a debate on NIDS (network-based intrusion-detection system) testing erupted, a completely nontechnical question burst into our inboxes: What's the ROI on an IDS solution? You expect to hear about packet normalization and application evasion techniques on an IDS list, but ROI discussions? Certainly not.

The thread brought about interesting comments, good pointers to articles and a few proposed formulas for calculating potential ROI values for an IDS deployment.

One proposal suggested calculating the annualized loss expectancy (ALE) using asset values, the percentage of loss expected per incident, and the total number of estimated incidents. By determining the ALE, you could compare it to the costs of maintaining the IDS solution (essentially, IDS' TCO), which could then be used to calculate the technology's ROI. A team from the University of Idaho submitted a paper in which it proposed factoring in annual costs from an estimated number of intrusions. (Users wishing to investigate the actual equations can read the thread.)

Obviously, people put a great deal of thought behind many of these ROI proposals, but it's difficult to "plug and chug" with these formulas because there are too many unknowns. For example, most organizations are unable to quantify -- fiscally -- their digital assets. Many organizations are unaware of how many actual security incidents they have faced, nor have they tracked how much those incidents have cost.

These first-run ROI models may leave some organizations with more questions than answers. But that's not necessarily a bad thing. Organizations must start answering some basic questions, primarily, what do I have and how much is it worth to me? Asset identification, as trite as it may sound, is still a cornerstone. By gathering answers to some of the basics, organizations can begin to understand the true security risks and, in turn, potential returns on security investments.

As security spending increases, so will the need to represent issues more traditionally. Refined ROI formulas and methodologies are sorely needed. Larger data sets are sorely needed. There's a long road ahead of us, but the closer we come to tangible numbers, the closer we come to answering the really important questions, like how does our beverage budget compare to our security budget?

Send your comments on this column to Greg Shipley at gshipley@neohapsis.com.







Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service