Expert Advice Community

Guest

ROSI

  Quote
Guest
Guest user Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

ROSI

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 13, 2016

I'm interested in ROSI, I mean malicious activity and unintentional human error and natural disaster and force majeure
 

Answer:

ROSI (Return on Security Investment) is a parameter that relates the investment on information security with the economic benefits that this will bring to the business. The calculation of the ROSI can be based on:
- Costs of an incident by taking into account all the relevant costs if an incident occurs and the probability of incident. There are some type of incidents: Malicious activity (virus, trojan horses, etc.), unintentional human error (delete critical information by error, etc.), system errors/malfunctions (hardware failure, etc.), natural disaster & force majeure (earthquake, flood, etc.)
- Costs of security measures/controls and the level to which the risk of this incident would decrease because of such mitigation
Do you need to calculate the ROSI? This free tool can be very useful for you “Free Return on Security Investment Calculator” : https://advisera.com/27001academy/free-tools/free-return-security-investment-calculator/  
And this article can be also interesting for you “Is it possible to calculate the Return on Security Investment (ROSI)?” : https://advisera.com/27001academy/blog/2011/06/13/is-it-possible-to-calculate-the-return-on-security-investment-rosi/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Aug 26, 2019 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 benefits