80 likes | 154 Views
Explore the costs involved in implementing an information assurance policy to safeguard your organization's data. Learn about budget allocation, hidden costs, and strategies for writing, maintaining, and enforcing policies for optimal security.
E N D
Information Assurance Policy Costs • by James Rosen
Some Figures • Deloitte & Touche, 2003: Financial services companies are spending approximately 6% of their IT budgets on information security • IDC: The market for web intrusion protection services and products is expected to increase to nearly US $700,000,000 by 2006. What was the real figure? • ACM: Malicious code caused $13b in costs in 2001 • Schneier: A Moscow company charges $10k for risk analysis for small companies; Verisign's subsidiary iDefense offers bounties for finding holes • IDG News: Corp's should spend 4-6% on InfoSec
Categories • Writing the Policy • Maintaining the Policy • Enforcing the Policy • Hidden Costs (Externalities)
Writing the Policy • cataloging resources (incl data types) • researching potential threats • evaluating risk to different resources • Getting input from each stakeholder • drafting the paper
Maintaining the Policy • Research • Analyzing new aspects of the business • New technologies • New threats • continuing education for Security Team • OCTAVE training: several $k, plus several days paid non-work time for a small team • NSA's IAM training (similar)
Enforcing the Policy • Initial training & communications • Vulnerability evaluation • Patching • Equipment • Firewalls • Multi-factor authentication • Surveillance • event response • Re-training employees • Firing or disciplining employees • On-call IT/Security response team
Hidden Costs • short-term costs resulting from being bound by the IAP • e.g. limitations in practices, technology choices, etc. • Ideally, offset in the long-term