Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

A Chief Information Security Officer (CISO) is presenting the current state of information security to the executive management. To justify ongoing and future security investments, the CISO wants to demonstrate the financial benefits of the security program. Which of the following approaches BEST illustrates the economic value of security to the business?

  1. APresenting the total number of security incidents successfully blocked by the security controls.
  2. BDetailing the compliance status with all relevant industry regulations and standards.
  3. CCalculating the Annualized Loss Expectancy (ALE) before and after implementing security controls.
  4. DBenchmarking the organization's security maturity against industry best practices and competitors.
Show answer & explanation

Correct answer: C. Calculating the Annualized Loss Expectancy (ALE) before and after implementing security controls.

To justify security investments to executive management, particularly regarding 'financial benefits' and 'economic value', it's crucial to speak in monetary terms. Calculating the ALE before and after controls directly quantifies the financial risk reduction achieved by the security program, clearly demonstrating its economic value and ROI.

Why the other options are wrong

  • A. While showing activity, the number of blocked incidents does not directly translate to financial value or ROI.
  • B. Compliance is important, but it's a cost of doing business, not a direct measure of economic value or ROI.
  • D. Benchmarking shows relative posture but not the direct financial benefit or ROI of specific investments.

Risk-Adjusted ROI for Security

A measure of the financial return on security investments, considering the reduction in potential losses (risk mitigation) achieved by those investments.

  • Quantifies security's financial value.
  • Helps prioritize security spending.
  • Aligns security with business objectives.

Memory trick: Show them the money saved, not just the threats avoided.

More Information Security Risk Management questions