Budgeting for Information Security and ROI Approach
Bibliographic record
Abstract
Abstract:- Information security expenditure involves heavy investment in people, processes and tools. Information system security projects cover a number of non-quantifiable factors not amenable to simplistic cost benefit or ROI analysis. Associated cost/benefits are contingent upon uncertain factors, including level, type, nature and extent of security. Moreover security projects have to comply and deal with statutory issues and differ from case to case. For such projects, the expected productive life, the training period, the periodicity and quantum of benefits/inflows and the expected future outflows required for maintenance, have to be estimated, making quantification complex. The proposed method uses the concept of Total Cost of Ownership, consisting of Direct and Indirect Costs of deploying and maintaining the system for base level security. Option price based ROI method is used to create the second metric for additional level of advanced security. We use the metrics to estimate the net pay offs of the different choices under different probable conditions. The result is a decision matrix to assist stakeholders in decision-making. Key-Words:- Information security expenditure, non-quantifiable factors in IT Security Projects, cost
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.007 | 0.016 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.003 | 0.003 |
| Science and technology studies | 0.001 | 0.001 |
| Scholarly communication | 0.003 | 0.003 |
| Open science | 0.001 | 0.001 |
| Research integrity | 0.001 | 0.001 |
| Insufficient payload (model declined to judge) | 0.008 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".