The end of ROSI, one can but hope

information security: RoSI: R.I.P.

There's an interesting link over at Axel Eble's blog to a report that, hopefully, people are geting round to the throught that security is not something that you calculate the R.O.I on, more that you view it like insurance or fire control system, as loss avoidance.

The problem with calculating ROSI has always been quantification, and it's always struck me that people that suggest it as a good way of justifying security spend, come up very short on specifics when asked, how it would actually be implemented.....

About this Entry

This page contains a single entry by Rory2 published on April 23, 2004 9:30 PM.

Online Portscan was the previous entry in this blog.

Prelude IDS is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Pages

Powered by Movable Type 4.37

About this Entry

This page contains a single entry by Rory2 published on April 23, 2004 9:30 PM.

Online Portscan was the previous entry in this blog.

Prelude IDS is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.