Feature
News
7/19/2005
12:10 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

First And Foremost, Security Must Make Business Sense

Return on investment analysis is useful, but prioritizing security projects and focusing on business objectives are necessities.

Determining a return on investment isn't the only way to pitch a security project. Although it's true that hard metrics often trump passionate please (see "How To Pitch a Winning Project"), business drivers often trump numbers. Making good business decisions is the goal. Quantitative methods may provide useful input, but they're no substitute for careful reasoning about which security expenditures will help make your enterprise more successful overall.

Take the way one leading financial institution prioritizes its security spending. The company has a baseline of security spending that is nondiscretionary and necessary to satisfy the its regulatory and internal audit requirements. By consistently implementing these policies, the company ensures that no line of business becomes the weakest link that undermines the security of the entire enterprise.

ROI and other quantitative analysis may help provide a common framework with other technology investments, but you should prioritize and justify security spending by having a solid discussion of your application objectives and their exposures. Because so much of today's security budget is dedicated to mandatory items, only a fraction is left for discretionary projects. So you must have a healthy debate regarding how best to spend this money. Quantitative techniques play only a limited role in prioritizing these security projects.

Risk Is Relative

Risk-management philosophy pervades today's companies, and it's apparent on both the revenue- and cost-generating sides of the house. Using a risk-management approach, many companies, for instance, accept a priori that all its activities have risks. The challenge then becomes spending your resources to protect the business from likely security threats. This adds a third dimension to the classic cost-benefit analysis. Using the risk-management approach, you are assessing relative or proportional contribution, rather than absolute contribution, when comparing prospective projects.

Latest Issue of Secure Enterprise Magazine

Read more >>

You can apply this approach to just about any kind of company. Begin this analysis by categorizing your potential security projects according to their business impact. Here are the categories, in order of importance:

• Enablement: Your enterprise will earn the most return on its investment from security projects that serve as obvious enablers to lines of business. These are projects that generate incremental revenue and profit, such as a mutual authentication system that allows straight-through processing or automating back-office workflow.

• Protection of key assets: This is a set of investments necessary to protect your current revenue streams, such as improving the backup and off-site storage procedures for your credit card operation. Weigh projects in this category against the amount of revenue at risk.

• Opportunity: Opportunistic investments typically result in cost savings or process improvements, such as an integrated firewall-management system that improves control over rule changes and provides reporting features that reduce the cost and time spent auditing the firewalls. Any investments in corporate infrastructure that provide long-term payoffs fall into this category.

• Nice To Have: Projects in this category have a low probability of getting funded. They make security and IT jobs easier, but are generally a very tough sell.

Exercise Your Options

It makes sense to apply quantitative methodology to your security projects only after you've carefully studied the business impact of these projects. For most organizations, prioritizing security spending is not about approving a single project. Rather, it's about constructing a portfolio of projects that fit within the budget. If time is tight, so do so only for the trickier decisions.

Say you are a financial institution with a discretionary security budget of $1.5 million (after funding your required security expenditures). Your have several worthwhile projects vying for funding, but they add up to $2.5 million--way over budget:

• Conduct a long-delayed assessment of the company's international, direct-inward dial telephone lines for security exposures and cost reduction. Cost: $300,000.

• Develop a handheld security strategy to enable the safe deployment of a CRM (customer-relationship management) application for investment advisers. Cost: $100,000.

• Develop a security dashboard so senior management can understand the company's security status at any time (this may be helpful in Section 404 Sarbanes-Oxley compliance). Cost: $300,000.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
The Agile Archive
The Agile Archive
When it comes to managing data, donít look at backup and archiving systems as burdens and cost centers. A well-designed archive can enhance data protection and restores, ease search and e-discovery efforts, and save money by intelligently moving data from expensive primary storage systems.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Government, May 2014
NIST's cyber-security framework gives critical-infrastructure operators a new tool to assess readiness. But will operators put this voluntary framework to work?
Video
Slideshows
Twitter Feed
Audio Interviews
Archived Audio Interviews
GE is a leader in combining connected devices and advanced analytics in pursuit of practical goals like less downtime, lower operating costs, and higher throughput. At GIO Power & Water, CIO Jim Fowler is part of the team exploring how to apply these techniques to some of the world's essential infrastructure, from power plants to water treatment systems. Join us, and bring your questions, as we talk about what's ahead.