Talk With an Expert

Quantifying Business Value of Information Security

Quantifying Business Value of Information Security (PDF, 2.20MB)Published: 14 Jul, 2009
Created by:
Eric Poole

been difficult to measure. For this reason some organizations forgo implementing security controls that could bring a positive return on investment to their organization. The goal of this paper is to familiarize the reader with risk management terminology, discuss how it can be applied to risk management and budgeting situations and present a quantitative risk management valuation process to show the benefit of a security control to the business. Using the methodology outlined in this paper the reader will be able to better describe to a business what the impact of security controls are on the bottom line of the organization.