Did you ever face a situation where you have been told that your security measures are too expensive? Or you find it very difficult to explain to your management what the consequences could be if an incident occurs?
Proving that it is worth investing in security is tough, but our Return on Security Investment (ROSI) calculator can help you. It's completely free.
Information Security & Business Continuity Academy, the largest online resource for the implementation of ISO 27001 and BS 25999-2 standards, has launched its free ROSI Calculator at http://www.iso27001standard.com/en/rosi/return-on-security-investment
This Calculator will help to solve one of the biggest problems information security and IT professionals have – how to prove to the top management that an investment in information security makes sense.
The definition of Return on Security Investment is the following: ROSI = monetary risk mitigation − cost of control. Therefore, a security investment is judged to be profitable, if the risk mitigation effect is greater than the expected costs. (Source: Christian Locher, Methodologies for evaluating information security investments, 2005).
This is the most detailed ROSI Calculator that can be found on the Internet, and it aims to calculate as precisely as possible whether the potential decrease of security incidents (i.e. the risk mitigation) will outweigh the investment in security measures. The calculation is performed in two steps:
- Step #1 - the costs of an incident are calculated by taking into account all the relevant costs if an incident occurs and the probability of incident occurrence.
- Step #2 - the costs of security measures/controls are calculated, and the level to which the risk of this incident would decrease because of such mitigation.
- The final result (after Step #2) is the calculation whether the gain (the risk decrease) is higher than the needed investment (security measures/controls).
The use this Calculator requires no expert knowledge about information security or finance, and it requires gathering existing data on costs within the company, security measures and potential incidents. It can be used by both IT and security professionals, and finance analysts.
Use of the ROSI Calculator is completely free – it can be found at http://www.iso27001standard.com/en/rosi/return-on-security-investment




