A Chief Information Security Officer (CISO) is presenting a proposal for a significant investment in a new security information and event management (SIEM) system. The board of directors, while understanding the need for cybersecurity, questions the return on investment (ROI) and how this investment aligns with the organization's broader business objectives. To gain board approval, the CISO should PRIMARILY focus on:
- AComparing the proposed SIEM system's cost with industry-average SIEM prices.
- BEmphasizing the competitive advantage gained by having a state-of-the-art security system.
- CExplaining how the SIEM will reduce the likelihood of specific cyberattacks and the associated financial and reputational impacts, aligning with strategic goals.
- DDetailing the technical specifications and advanced features of the SIEM system.
Show answer & explanationAnswer & explanation
Correct answer: C. Explaining how the SIEM will reduce the likelihood of specific cyberattacks and the associated financial and reputational impacts, aligning with strategic goals.
Boards are interested in how investments support business objectives. Articulating the SIEM's role in reducing specific risks, quantifying financial and reputational impacts, and linking these to strategic goals demonstrates business acumen and justifies the ROI.
Why the other options are wrong
- A. Cost comparison is relevant but does not explain the business value or strategic alignment, which is the board's primary focus for approval.
- B. While competitive advantage might be a byproduct, it's a less direct and quantifiable argument than demonstrating tangible risk reduction and impact on strategic objectives.
- D. Technical specifications are not the primary concern for the board; they want to understand business value and impact.
Business Case for Security Investment
The process of justifying security investments to senior leadership (e.g., board) by translating technical benefits into tangible business value, including risk reduction, financial impact mitigation, and alignment with strategic organizational objectives.
- Focuses on business outcomes, not just technical features.
- Quantifies financial and reputational impacts.
- Aligns security with strategic goals for board approval.
Memory trick: For the board, security ROI means linking tech to business gain and strategic aim.