Title | ||
---|---|---|
Framework for Calculating Return on Security Investment (ROSI) for Security-Oriented Organizations |
Abstract | ||
---|---|---|
Today’s business environment is extremely dynamic and reliant on innovative Information Technology (IT). Such dependence upon technology leads to an increased rate of successful cyber-attacks whose impact is greater than ever. Due to the exponential increase in security breaches, companies should secure their IT systems by adopting appropriate risk management framework. Organizations have to make justified investments in cyber security. However, it is quite challenging to convince higher management to invest in security measures, since such investments cannot be exactly translated into profits. The Return on Security Investment (ROSI) holds great importance to justify such security investments. A large number of ROSI solutions have already been proposed. However, these solutions do not provide any approach to analyze the impact of single security investment upon whole infrastructure. Furthermore, uncertainty of security incident emerges as another important challenge. The existing ROSI frameworks work on approximations, which can be influenced by employees’ exposure and experience, resulting in wrong estimation. The objective of this research is to propose a comprehensive framework to measure ROSI effectively by overcoming gaps in the traditional approaches. The framework has been validated with the help of Common Vulnerability Security System (CVSS) attack dataset. The results show that the annual loss in the absence of security mechanisms is very high i.e. 585,553. However, by following the proposed systematic approach to determine ROSI, it can be reduced to 146,388 which is comparatively low. As a result, organization can save its resources, time, money, trust, and reputation in the market. |
Year | DOI | Venue |
---|---|---|
2019 | 10.1016/j.future.2018.12.033 | Future Generation Computer Systems |
Keywords | Field | DocType |
ROSI calculations,CVSS,Information security,Annual loss,Investment decisions,Bayesian theorem | CVSS,Risk management framework,Security system,Information technology,Computer science,Business environment,Risk analysis (engineering),Vulnerability,Profit (economics),Reputation,Distributed computing | Journal |
Volume | ISSN | Citations |
95 | 0167-739X | 0 |
PageRank | References | Authors |
0.34 | 12 | 5 |
Name | Order | Citations | PageRank |
---|---|---|---|
Tahreem Yaqoob | 1 | 2 | 1.39 |
Azka Arshad | 2 | 0 | 0.34 |
Haider Abbas | 3 | 391 | 43.88 |
M. Faisal Amjad | 4 | 21 | 8.90 |
Narmeen Shafqat | 5 | 0 | 0.34 |