Understand the business case for security

Opinion
Mar 8, 20053 mins

* Guest writer on the business value of information security

My friend and colleague Don Holden, adjunct professor of information assurance in the MSIA Program at Norwich University, is also an experienced security consultant and an executive with Concordant. He recently wrote an article for our students that I hope readers will find thought-provoking. Here it is.

My friend and colleague Don Holden, adjunct professor of information assurance in the MSIA Program at Norwich University, is also an experienced security consultant and an executive with Concordant. He recently wrote an article for our students that I hope readers will find thought-provoking. Here it is:

Bob Blakley, the chief scientist for security and privacy at IBM, notes that the current approach to security has failed, and that there is no viable technical model. He calls for a new industry approach based upon a business model in which technical models will evolve.

Although Blakley was speaking as a vendor, we, as security managers, also need to be able to state the business case and the economic value for the security function. We need to understand and communicate the economic costs of both providing security and failing to provide security. I knew several chief information security officers (CISO) at major banks who lost their jobs last year when the Federal Reserve sent letters reporting security deficiencies to their boards of directors. In at least one instance I believe this was a result of a failure of vision: The bank’s business units responsible for implementing corporate security policies did not see the economic value of security and failed to adequately implement security controls. 

So, we need to have metrics that show how well the security function is performing and what the costs and the business benefits are. We need metrics that show the cost of failed security, such as when an e-mail server is taken down due to a virus or customers’ account information is compromised. If we understand the business value of security, we can also allocate back to the business units their share of the cost of providing security. We can make better purchasing decisions if we know the cost of installing patches due to poor product quality. And we can make better risk-management trade-offs if we know both the cost of the security measure and the expected loss it will prevent. With recent regulations such as the Health Insurance Portability and Accountability Act and the Gramm-Leach-Bliley Act, affected companies need to have a good understanding of the costs involved in these risk management trade-offs.

When we understand that security is a business issue and competes with other business issues for resources, we will have to understand financial rules such as how capital budgeting decisions are made using return on investment or Net Present Value, and when security costs should even be considered a capital item.

By the way, those fired CISOs are now well-paid security consultants.