Nothing Special   »   [go: up one dir, main page]

Gesellschaft für Informatik e.V.

Lecture Notes in Informatics


Information Systems Technology and its Applications 6th International Conference ISTA`2007 May 23-25, 2007, Kharkiv, Ukraine P-107, 21-32 (2007).


2007


Editors

Heinrich C. Mayr (ed.), Dimitris Karagiannis (ed.)


Contents

Return on security investments - design principles of measurement systems based on capital budgeting

J. V. Brocke , C. Buddendick and G. Strauch

Abstract


IT-security has become a vital factor in electronic commerce nowadays. Thus, investments have to be made in order to safeguard security. However, the benefits of these investments are often hardly visible. In most cases, such investments are made only retroactively, after incidents occur. It is necessary to measure the value before preventing incidents. For this purpose ROSI (Return on Security Investments) has gained enormous attention in research and practice. In this paper, we discuss this measure from a methodological perspective. We argue that existing approaches for calculating ROSI lack a sound methodological basis and that these approaches can be misleading for decision support. In contrast to these approaches, we suggest a new approach for the calculation of ROSI on a capital budgeting basis.


Full Text: PDF


Last changed 04.10.2013 18:14:06