首页> 外文会议>WSEAS International Conferences >Budgeting for Information Security and ROI Approach
【24h】

Budgeting for Information Security and ROI Approach

机译:用于信息安全和ROI方法的预算

获取原文

摘要

Information security expenditure involves heavy investment in people, processes and tools. Information system security projects cover a number of non-quantifiable factors not amenable to simplistic cost benefit or ROI analysis. Associated cost/benefits are contingent upon uncertain factors, including level, type, nature and extent of security. Moreover security projects have to comply and deal with statutory issues and differ from case to case. For such projects, the expected productive life, the training period, the periodicity and quantum of benefits/inflows and the expected future outflows required for maintenance, have to be estimated, making quantification complex. The proposed method uses the concept of Total Cost of Ownership, consisting of Direct and Indirect Costs of deploying and maintaining the system for base level security. Option price based ROI method is used to create the second metric for additional level of advanced security. We use the metrics to estimate the net pay offs of the different choices under different probable conditions. The result is a decision matrix to assist stakeholders in decision-making.
机译:信息安全支出涉及人们,流程和工具的重量投资。信息系统安全项目涵盖了许多不可避免的因素,不适合简单的成本效益或投资回报率分析。相关成本/福利在不确定因素的情况下,包括水平,类型,性质和安全程度。此外,安全项目必须遵守和处理法定问题,与案件不同。对于此类项目,必须估计预期的生产寿命,培训期,培训期,福利/流入以及维护所需的预期未来外流,使得量化复杂。该方法采用总体拥有成本的概念,包括部署和维护基本级安全系统的直接和间接成本。选项基于价格的ROI方法用于创建第二个度量标准,以获得额外的高级安全性。我们使用指标在不同可能条件下估计不同选择的净额净化。结果是决策矩阵,以帮助决策的利益相关者。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号