...
首页> 外文期刊>Information Systems Control Journal >Pay Today or Pay Later-Calculating ROI to Justify Information Security and Compliance Budgets
【24h】

Pay Today or Pay Later-Calculating ROI to Justify Information Security and Compliance Budgets

机译:立即付款或以后计算投资回报率,以证明信息安全性和合规性预算合理

获取原文
获取原文并翻译 | 示例
           

摘要

Why do businesses need to calculate return on investment (ROI) for information security? Is the assurance that its network/information technology (IT) infrastructure is secure not good enough? The answer is no, not when information security is viewed as a cost to the business. The only way to get the board of directors to pay any kind of attention is to address ROI. IT departments have traditionally been viewed as cost centers, though they have learned to provide a business case analysis for IT initiatives. Information security departments are trying to figure out how to do the same thing. They cannot sell security initiatives based on fear anymore. Now, they must come up with justifications, complete with the dreaded metrics or hard financial facts. The business case needs to show specifically how potential costs associated with liability caused by security breaches may be minimized by implementing a sound security infrastructure. This can be accomplished by allowing a third party to do a security audit that provides evidence of security risks.
机译:为什么企业需要计算信息安全的投资回报率(ROI)?对其网络/信息技术(IT)基础结构的安全性的保证是否还不够好?答案是否定的,当信息安全被视为企业的成本时,答案是否定的。引起董事会关注的唯一方法是解决投资回报率。传统上,IT部门被视为成本中心,尽管他们已学会为IT计划提供业务案例分析。信息安全部门正试图弄清楚如何做同样的事情。他们再也不能基于恐惧来出售安全措施了。现在,他们必须提出理由,并加上可怕的指标或困难的财务事实。该业务案例需要具体显示如何通过实施完善的安全基础结构来最大程度地减少与安全漏洞引起的责任相关的潜在成本。这可以通过允许第三方执行提供安全风险证据的安全审核来实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号