<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ERE-Security Blog &#187; Cost of IT Security Compliance</title>
	<atom:link href="http://ere-security.com/blog/tag/cost-of-it-security-compliance/feed" rel="self" type="application/rss+xml" />
	<link>http://ere-security.com/blog</link>
	<description>NERC CIP, NERC CIP compliance, SCADA, SOX, digital certificates, harmonized TRA, privacy compliance audit, CSOX compliance audit,  it security audit, information security auditors, IT security auditors, web security auditors, information security audit, information security auditor, security policy document</description>
	<lastBuildDate>Sat, 21 May 2011 00:10:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Quantifying Risk and Cost of IT Security Compliance:  Part 5</title>
		<link>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-5</link>
		<comments>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-5#comments</comments>
		<pubDate>Thu, 18 Mar 2010 19:38:06 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Cost of IT Security Compliance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Risk of IT Security Compliance]]></category>

		<guid isPermaLink="false">http://ere-security.com/blog/?p=190</guid>
		<description><![CDATA[This week’s blog is Part 5 of 5 parts of a series.
You may not have heard of the IT security team called ROSI; it stands for return on security investment.  It’s really the same as ROI but it helps to convey to executives that a business case is being build according to best security practices.
Determining [...]]]></description>
			<content:encoded><![CDATA[<p>This week’s blog is Part 5 of 5 parts of a series.</p>
<p>You may not have heard of the IT security team called ROSI; it stands for return on security investment.  It’s really the same as ROI but it helps to convey to executives that a business case is being build according to best security practices.</p>
<h3>Determining if ROSI Objectives are Met</h3>
<p>Tires meet the road when it is time to determine whether or not ROSI objectives for security / policy / compliance have been met.  Conveying this determination is essential to building (or destroying) credibility of the group who made the mitigation recommendations in the first place.</p>
<p>Determining ROSI is quite simple. The actual costs resulting from events are compared with the projected costs after mitigation.  If mitigation was successful, then the actual costs should be near or below the projected costs.  This information can be presented as an updated version of Exhibit 3, shown as</p>
<p><strong>Exhibit 5</strong> – Projected vs. Actual Cost of Losses.  For purposes of accuracy new trends that developed in the security environment over the period of study should be considered.  If new trends increased the cost of losses, and the effect can be quantified, then the results should be reported accordingly.</p>
<p><strong>Exhibit 5</strong> – Projected vs. Actual Cost of Losses  This exhibit can’t be shown in the blog but you can see it in a whitepaper on the ERE web site www.ere-security.ca</p>
<p><strong>Summary</strong></p>
<p>The task of getting approval for a sufficient budget for IT security, privacy compliance, and IT regulatory compliance is usually frustrating and arduous. The task can be made easier by presenting the IT Security Governance body with simple to understand graphics, rather than with complex business plans.  The graphs should depict the relationship between the cost of risk and the cost of mitigation.  The presentation process should occur both at budget request time to show the intended plan, and after the budget cycle to show the actual results.  Hopefully the results trump the plan.</p>
<p><strong>Sources of Information</strong></p>
<p>(1) ANZ 4360:2004 Risk Management Standard http://www.ncsi.com.au/as4360.html</p>
<p>(2) Calculations of ALE are based upon The Official CISSP CBK, 2009, published by ISC2 www.isc2.org</p>
<p>(3) NIST- 88 series http://csrc.nist.gov/publications/PubsSPs.html</p>
<p>(4) ISACA: CISM Review Manual 2010 www.isaca.org</p>
<p>(5) PCI Security Standards – PCI https://www.pcisecuritystandards.org/index.shtml</p>
<p>(6) NERC – CIP 02 – 09 www.nerc.com</p>
<p>(7) ROSI  Calculating Security Return on Investment, Don O’Neil Software Engineering Institute, 2007, CERT</p>
<p>https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/677-BSI.html</p>
<p>(8) Gartner whitepaper:“Incorporating Security into the Enterprise Architecture Process, Jan 2006 www.gartner.com</p>
<p>(9) EISA: http://en.wikipedia.org/wiki/Enterprise_information_security_architecture</p>
<p>(10) The U.S. Department of Defense (DoD) Architecture Framework (DoDAF) http://www.architectureframework.com/dodaf/</p>
<p>(11) Extended Enterprise Architecture Framework (E2AF) from the Institute For Enterprise Architecture Developments. http://www.enterprise-architecture.info/</p>
<p>(12) Federal Enterprise Architecture of the United States Government (FEA) http://www.whitehouse.gov/omb/e-gov/fea/</p>
<p>(13) Capgemini&#8217;s Integrated Architecture Framework</p>
<p>http://www.capgemini.com/services-and-solutions/technology/soa/overview/ent_architecture/iaf/</p>
<p>(14) NIH Enterprise Architecture Framework http://enterprisearchitecture.nih.gov/About/Approach/Framework.htm</p>
<p>(15) Open Security Architecture ]http://www.opensecurityarchitecture.org/cms/index.php</p>
<p>(16) The Open Group Architecture Framework (TOGAF) http://www.opengroup.org/architecture/togaf8-doc/arch/</p>
<p>(17) Zachman Framework http://www.zifa.com/</p>
<p>(18) Control points from the COBIT framework.  http://www.isaca.org/Template.cfm?Section=COBIT6&amp;Template=/TaggedPage/TaggedPageDisplay.cfm&amp;TPLID=55&amp;ContentID=7981</p>
<p>Have a secure week.</p>
<p>Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP</p>
<p>ERE Information Security and Privacy Compliance Auditor</p>
<p>www.ere-security.ca</p>
]]></content:encoded>
			<wfw:commentRss>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quantifying Risk and Cost of IT Security Compliance:  Part 4</title>
		<link>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-4</link>
		<comments>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-4#comments</comments>
		<pubDate>Wed, 24 Feb 2010 20:10:35 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Cost of IT Security Compliance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Risk of IT Security Compliance]]></category>

		<guid isPermaLink="false">http://ere-security.com/blog/?p=185</guid>
		<description><![CDATA[This week’s blog is Part 4 of 5 parts of a series.
If you are in security no doubt you have been challenged by management about your security expenditures.  I have often heard executives say that they regret authorizing sufficiently large security budgets because they can’t tell if the expenses were worthwhile.  It’s a good point.  [...]]]></description>
			<content:encoded><![CDATA[<p>This week’s blog is Part 4 of 5 parts of a series.</p>
<p>If you are in security no doubt you have been challenged by management about your security expenditures.  I have often heard executives say that they regret authorizing sufficiently large security budgets because they can’t tell if the expenses were worthwhile.  It’s a good point.  I’ll try to address it in this blog.</p>
<p><strong> </strong></p>
<p><strong>Measuring the Effectiveness of Mitigation</strong></p>
<p><strong></strong>It is paramount to close the risk management loop by comparing planned and actual results of mitigation.</p>
<p>Goal is to clearly identify if risk level has changed and what consistent metrics will be used to base a conclusion. Once again, this may be difficult to accomplish directly, but there certainly are metrics for measuring and comparing the results of implementing mitigation. The metrics should always:</p>
<ol>
<li>Produce repeatable, consistent results.</li>
<li>Be understandable.</li>
<li>Be reasonably simple to use over time.</li>
</ol>
<p>The following is a good starting list of metrics that can be used for consistently measuring and reporting on risk:</p>
<ol>
<li>Architectures for measuring risk – Enterprise Information Security Architecture (EISA) <strong>(8), (9)</strong>
<ol>
<li><strong>a. </strong><a title="DODAF" href="http://en.wikipedia.org/wiki/DODAF">The U.S. Department of Defense (DoD) Architecture Framework (DoDAF)</a>. <strong>(10)</strong><strong> </strong></li>
<li>Extended Enterprise Architecture Framework (E2AF) from the Institute For Enterprise Architecture Developments. <strong>(11)</strong></li>
<li><a title="Federal Enterprise Architecture" href="http://en.wikipedia.org/wiki/Federal_Enterprise_Architecture">Federal Enterprise Architecture</a> of the United States Government (FEA).  <strong>(12)</strong></li>
<li>Capgemini&#8217;s Integrated Architecture Framework. <strong>(13)</strong></li>
<li>NIH Enterprise Architecture Framework. <strong>(14)</strong></li>
<li>Open Security Architecture. <strong>(15)</strong></li>
<li><a title="TOGAF" href="http://en.wikipedia.org/wiki/TOGAF">The Open Group Architecture Framework (TOGAF)</a>.<strong> (16)</strong></li>
<li><a title="Zachman Framework" href="http://en.wikipedia.org/wiki/Zachman_Framework">Zachman Framework</a>.  <strong>(17)</strong></li>
<li>Control points from the COBIT framework.  <strong>(18)</strong></li>
<li>Vulnerability assessments.</li>
<li>Penetration tests.</li>
<li>Time trends in frequency of occurrence and the real costs of security events, privacy violations, and policy compliance violations.</li>
<li>Time trends in cost to recover from events.</li>
<li>Time trends in frequency of policy compliance violations that do not necessarily cause any financial losses, such as identifying Trojans, viruses, rootkits, unauthorized logins, attempted port scans, frequency of dropped packets, frequency of password lifecycle, breaches, and frequency of rescheduled / cancelled IT Security Governance meetings with business managers.</li>
</ol>
</li>
</ol>
<p>This part of the series may be a little dry.  In fact it is very dry.  But if you ever want to have a process done “by the book” many of my references will come in handy.  If you can take another “dry” blog, the next blog will cover the same subject but from a return on investment perspective.  I hope it will be helpful!</p>
<p>Have a secure week.</p>
<p>Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP</p>
<p>ERE Information Security and Privacy Compliance Auditor</p>
<p><a href="http://www.ere-security.ca/"><strong>www.ere-security.ca</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-4/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quantifying Risk and Cost of IT Security Compliance:  Part 3</title>
		<link>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-3</link>
		<comments>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-3#comments</comments>
		<pubDate>Thu, 18 Feb 2010 02:33:09 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Cost of IT Security Compliance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Risk of IT Security Compliance]]></category>

		<guid isPermaLink="false">http://ere-security.com/blog/?p=181</guid>
		<description><![CDATA[This week’s blog is Part 3 of 5 parts of a series.
I think that too often security people try to “fix” every security problem.  That is not realistic or required.  Many times, it is sufficient to just identify security risks and problems to management and get them to make a decision on how they want [...]]]></description>
			<content:encoded><![CDATA[<p>This week’s blog is Part 3 of 5 parts of a series.</p>
<p>I think that too often security people try to “fix” every security problem.  That is not realistic or required.  Many times, it is sufficient to just identify security risks and problems to management and get them to make a decision on how they want to deal with it.</p>
<p>But the operative phrase is “decision on how they want to deal with it.”</p>
<h2><strong>Calculating the Cost of Mitigation</strong></h2>
<p>Security professionals are well acquainted with determining the costs of mitigation.  Senior executives sometimes think they too are familiar with these costs, based upon ads they read about anti-virus and firewall technology.</p>
<p>The danger here is that it is too easy for all concerned to focus on technology as the primary mitigation for security and compliance.  It is well documented in standards published by industry experts such as NIST- 88 series (3), ISACA CoBIT (4),  PCI Security Standards – PCI (5),  and NERC – CIP 02 – 09 (6).</p>
<p>It is well advised to consider mitigation steps that include:</p>
<p>1. Re-engineering processes, both technological and people processes.</p>
<p>2. Policy – people and technology</p>
<p>3. Technical security.</p>
<p>4. Physical security.</p>
<p>5. People processes.</p>
<p>6. Training and awareness.</p>
<p>7. Third party auditing to verify the effectiveness of all the above.</p>
<p>From an IT Security Governance perspective the optimal cost point for mitigation is where the total costs of risk and mitigation are lowest.  This point can be graphically determined as in Exhibit 3 – Optimal Cost Point for Mitigation.</p>
<p><strong>Exhibit 3</strong> &#8211; Optimal Cost Point for Mitigation (3) This exhibit can’t be shown in the blog but you can see it in a whitepaper on the ERE web site www.ere-security.ca</p>
<p>Once mitigation costs are determined, it is important to express to the IT Security Governance committee that mitigation only goes so far, and that some residual risk remains even after spending on mitigation.  The residual risk can be expressed as the cost of risk that remains after mitigation is implemented.  As shown in Exhibit 4 – Mitigation Cost vs. Chance of Event Occurrence, expenditures on mitigation reduce the cost of exposure to risk.</p>
<p><strong>Exhibit 4</strong> – Mitigation Cost vs. % Chance of Event Occurrence This exhibit can’t be shown in the blog but you can see it in a whitepaper on the ERE web site www.ere-security.ca</p>
<p>The IT Security Governance Committee may decide to deal with residual risk by:</p>
<p>1. Accepting the risk.</p>
<p>2. Moving the risk (insurance).</p>
<p>3. Further mitigation.</p>
<h3>Calculating Return on Security Investment (ROSI) (7)</h3>
<p>Once the total cost of security mitigation is determined by including any costs for managing residual risk, then it is straightforward to calculate the return on security investment, as follows:</p>
<p><strong>ROSI = cost of mitigation  /  cost of risk</strong></p>
<p>When calculating ROSI it is important to allocate mitigation costs on a pro-rated basis across all costs of risk to which they apply.  In this way ROSI can be more accurately calculated and evaluated by each profit and loss manager and associated stakeholder.</p>
<p>The next blog will deal with figuring out if the cost of mitigation were worth it!</p>
<p>Have a secure week.</p>
<p>Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP</p>
<p>ERE Information Security and Privacy Compliance Auditor</p>
<p>www.ere-security.ca</p>
]]></content:encoded>
			<wfw:commentRss>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-3/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Quantifying Risk and Cost of IT Security Compliance:  Part 2</title>
		<link>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-2</link>
		<comments>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-2#comments</comments>
		<pubDate>Thu, 11 Feb 2010 19:53:02 +0000</pubDate>
		<dc:creator>Ron Lepofsky</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Cost of IT Security Compliance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Risk of IT Security Compliance]]></category>

		<guid isPermaLink="false">http://ere-security.com/blog/?p=175</guid>
		<description><![CDATA[This week’s blog is Part 2 of 5 parts of a series.
I know it is time consuming to do the analysis for building a business case.   I’ve seen the frustration on the faces of security types who present business cases for their budget and management gives them a rough time.
Hopefully these articles will be helpful.
The [...]]]></description>
			<content:encoded><![CDATA[<p>This week’s blog is Part 2 of 5 parts of a series.</p>
<p>I know it is time consuming to do the analysis for building a business case.   I’ve seen the frustration on the faces of security types who present business cases for their budget and management gives them a rough time.</p>
<p>Hopefully these articles will be helpful.</p>
<p>The next logical step would be to associate an actual cost to each event. Various methods can be used either separately or together with the implementation of an averaging metric to estimate the cost per occurrence of an event.  These methods may include:</p>
<p>1. Soliciting expert advice from financial management, lawyers, and risk management consultants.</p>
<p>2. Conducting a straw poll of stakeholders, each estimating the downside cost of an event.</p>
<p>3. Participating in a fact gathering survey of similar businesses, each of which provides factual and straw poll estimates of the cost of an event.</p>
<p>4. Purchasing statistical information from industry experts regarding the cost of an event.</p>
<p>5. Obtaining statistical information from industry associations about the cost of an event experienced by their membership.</p>
<p>Using a similar methodology, the next step is to determine the likelihood of an event occurring.  The most useful ways of expressing likelihood is in % chance of an event occurring in any one year.</p>
<p>However, any likelihood estimate should also be adjusted to account for changes in security environment.  There are typically evolving waves of new threats that may affect likelihood of occurrence, such as these previous waves:</p>
<p>1. Viruses</p>
<p>2. Malware of all sorts</p>
<p>3. DDOS</p>
<p>4. Identity Theft</p>
<p>The likelihood estimate can then be used to:</p>
<p>1. Qualitatively express cost vs. likelihood as in Exhibit 1 &#8211; Potential Cost vs. % Probability of Occurrence.</p>
<p>2. Calculate the quantitative Annual Loss Expectancy.</p>
<p>Exhibit 1 &#8211; Potential Cost vs. Probability of Occurrence (1)</p>
<p>This exhibit can’t be shown in the blog but you can see it in a whitepaper on the ERE web site www.ere-security.ca</p>
<p>Obviously want to prioritize the mitigation steps to dealing with high risk / high cost situations first.</p>
<h3>Annual Loss Expectancy (ALE) (2)</h3>
<p>The step from qualitative to quantitative risk analysis logically occurs at this point, where the team evaluating risk triages the results of Exhibit 1 in order to decide upon those risks where they intend to focus.</p>
<p>The potential cost of those risks can be determined by calculating their Annual Loss Expectancy.  The annual loss expectancy is the annualized estimated cost for the occurrence of any type of event.  This number is useful for comparison with the annual cost of mitigation.  ALE for an event is calculated by multiplying the previously determined of the cost of the event and the chance of its occurrence.</p>
<p><strong>Annual loss expectancy = cost of event x chance of occurrence</strong></p>
<p>Next week I will discuss the ins and outs of calculating the cost of minimizing risk and how to present this to the executives.</p>
<p>Have a secure week.</p>
<p>Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP</p>
<p>ERE Information Security and Privacy Compliance Auditor</p>
<p>www.ere-security.ca</p>
]]></content:encoded>
			<wfw:commentRss>http://ere-security.com/blog/quantifying-risk-and-cost-of-it-security-compliance-part-2/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

