Fill in Order Details

  • Submit paper details for free using our simple order form

Make Payment Securely

  • Add funds to your account. There are no upfront payments. The writer will only be paid once you have approved your paper

Writing Process

  • The best qualified expert writer is assigned to work on your order
  • Your paper is written to standard and delivered as per your instructions

Download your paper

  • Download the completed paper from your online account or your email
  • You can request a plagiarism and quality report along with your paper

Question 1. Information systems have become essential compon

Question 1. Information systems have become essential components in most organizations since they enhance efficiency in completing business and organizational operations. The security of this information systems is equally important to ensure their optimum functionality. Most organizations have heavily invested in information systems ranging from enterprise resource planning systems (ERP) to customer relationship management systems among others. These investments will be futile if their security is not guaranteed. Consequently, it is the role of the Computer Emergency Response Teams (CERT) together with the CISO to identify the security measures to be implemented in the organization. Information security efforts and implementation must be factored in the budget to meet various activities and procedures that go into the implementation. It is therefore important to consider the returns on investment that will be realized from information security. CERTs need to determine their cost-effectiveness in order to justify their budget usage as well as provide supportive claims for the next budgetary allocations. According to ENISA (2012), organizations mainly face challenges while accurately determining the cost and effectiveness of the respective information security activities. This is attributed to the fact that information security investment does not yield profits but it is a loss prevention investment. Despite this challenge, it is important that the organizations have a clear understanding of the benefits and the importance of investing in the security of information systems. Hence the need for Returns on security on investment calculation (Cavusoglu, Mishra & Raghunathan, 2004).Return on Investment (ROI) calculation is essential for justification of every budgetary allocation in any organization (Cavusoglu, Mishra & Raghunathan, 2004). Security is an investment in both public and private entities. Thus, the return on security investment (ROSI) must be done to determine and justify budgetary allocation for information system security. The ENISA work program states that the executive decision makers should know the impact of security. This will assist them to understand how much they should spend on security and how much the lack of security is going to cost. Additionally, they should identify the most cost-effective solutions that can be adopted (ENISA, 2012). This is only possible with a ROSI calculation.According to Sonnenreich, Albanese & Stout (2006), ROSI calculation will provide substantial quantitative answers to fundamental questions such as the amount an organization is paying for cyber security, the impact of the lack of cyber security in the organization and whether the security investment is enough. The method uses estimated potential loss (ALE), estimated risk mitigation and cost of the solution variables. This metric can also be applied to the Big Data Analytic (BDA) technology to determine its cost and the potential returns on investment (ENISA, 2012). ROSI calculations can be used to determine whether and organization particularly security companies can implement the technology and be able to realize returns on investment. Most notably, it enables decision makers in this respect to identifying the improvements to be gained from the technology and the losses from lack of implementation.ROSI calculation has some limitations that are mainly centered on the drawbacks of estimation and the Gordon and Loeb model of calculation. ROSI calculation is based on estimations which make it difficult to estimate the cost of cyber security incidents which vary depending on the environment. Additionally, the ROSI calculation can be manipulated very easily to serve the interest of the user. Secondly, the Gordon and Loeb model popularly used in the metric is an approximate model hence the resulting numbers must be treated with caution (ENISA, 2012).REFERENCESCavusoglu, H., Mishra, B., & Raghunathan, S. (2004). A model for evaluating IT security investments.Communications of the ACM,47(7), 87-92.European Network and Information Security Agency. (2012). Introduction to Return on Security Investment: Helping CERTs assessing the cost of (lack of) security. Heraklion, Crete, Greece: Author. Retrieved from https://www.enisa.europa.eu/activities/cert/other-work/introduction-to-return-on-security-investment/at_download/fullReportQuestion 2. Return on security investment (ROSI)-a practical quantitative model.Journal of Research and Practice in Information Technology,38(1), 45-56.Since network security products do not generate revenue, it is necessary to evaluate their worth by considering money saved from potential loss.The concept of Return on Security Investment (ROSI) provides a quantitative value in reference to the benefits attained through an investment in network security technology.“ROSI is calculated by the amount of risk reduced, less the amount spent, divided by the amount spent on controls, resulting in the net amount of risk per amount of control,” (Lindstrom, 2017).This value provides an indicator if the cost for security controls will outweigh the potential liability for penalties incurred due to network security breaches throughout the year.Cybersecurity technologies are the primary line of defense for network intrusions.It is essential that an organization remain abreast with the latest security software and strategies to defend against emerging security threats.Acquiring the most effective technology requires a cost benefit analysis to ensure a reasonable correlation of mitigated risk is met.ROSI is used to evaluate whether the amount of potential money saved is higher or lower than the recommended security control investment, (Schneier, 2008).This resulting loss or gain will provide guidance as to whether it is cost effective to purchase the recommended security measure or not.Network security threats are imminent to organizations and network resources everywhere.Increased accessibility of a network resource is generally parallel to an increase in security vulnerabilities.It is essential that all input values be as accurate as possible to assume an effective value of investment.“Unfortunately, the cost of cyber security incidents and annual rate of occurrence are hard to estimate and the resulting numbers can vary highly from one environment to another.These approximations are often biased by our perception of the risk and the ROSI calculation can be easily manipulated,” (ENISA, 2012).The routine probability for error limits the potential effectiveness of the ROSI metric and should be analyzed on a case by case bases.The ROSI calculation may even be utilized to evaluate the benefits of acquiring appropriate security measures for wearable technology.Take the smartwatch for example, as this product endures similar security vulnerabilities to a standard wireless network resource. There are third party antimalware security applications that may be purchased in addition to the use of advanced security and password features on the device, (Thomas, 2015).It is still necessary to confirm whether this investment in security control technology will yield savings or excess expenditures compared to the predicted losses without it.In this case, the resulting ROSI value may indicate that these low costing security applications may prove to be very cost effective, providing substantial savings against any potential futures losses incurred by a device security breach.ReferencesENISA. (2012). Introduction to return on security investment. Retrieved fromhttps://www.enisa.europa.eu/publications/introduction-to-return-on-security-investment/at_download/fullReportLindstrom, P. (2017). Return on security investment: the risky business of probability. Retrievedfrom http://searchsecurity.techtarget.com/opinion/Return-on-security-investment-The-risky-business-of-probabilitySchneier, B. (2008, September 2). Schneier on security: security ROI. Retrieved fromhttps://www.schneier.com/blog/archives/2008/09/security_roi_1.htmlThomas, K. (2015, April 15). How secure is your smartwatch? Retrieved fromhttp://www.welivesecurity.com/2015/04/15/secure-smartwatch/

WHAT OUR CURRENT CUSTOMERS SAY

  • Google
  • Sitejabber
  • Trustpilot
Zahraa S
Zahraa S
Absolutely spot on. I have had the best experience with Elite Academic Research and all my work have scored highly. Thank you for your professionalism and using expert writers with vast and outstanding knowledge in their fields. I highly recommend any day and time.
Stuart L
Stuart L
Thanks for keeping me sane for getting everything out of the way, I’ve been stuck working more than full time and balancing the rest but I’m glad you’ve been ensuring my school work is taken care of. I'll recommend Elite Academic Research to anyone who seeks quality academic help, thank you so much!
Mindi D
Mindi D
Brilliant writers and awesome support team. You can tell by the depth of research and the quality of work delivered that the writers care deeply about delivering that perfect grade.
Samuel Y
Samuel Y
I really appreciate the work all your amazing writers do to ensure that my papers are always delivered on time and always of the highest quality. I was at a crossroads last semester and I almost dropped out of school because of the many issues that were bombarding but I am glad a friend referred me to you guys. You came up big for me and continue to do so. I just wish I knew about your services earlier.
Cindy L
Cindy L
You can't fault the paper quality and speed of delivery. I have been using these guys for the past 3 years and I not even once have they ever failed me. They deliver properly researched papers way ahead of time. Each time I think I have had the best their professional writers surprise me with even better quality work. Elite Academic Research is a true Gem among essay writing companies.
Got an A and plagiarism percent was less than 10%! Thanks!

ORDER NOW


Consider Your Assignments Done

“All my friends and I are getting help from eliteacademicresearch. It’s every college student’s best kept secret!”

Jermaine Byrant
BSN

“I was apprehensive at first. But I must say it was a great experience and well worth the price. I got an A!”

Nicole Johnson
Finance & Economics

Our Top Experts

See Why Our Clients Hire Us Again And Again!


OVER

10.3k
Reviews

RATING
4.89/5
Average

YEARS
13
Mastery

Success Guarantee

When you order form the best, some of your greatest problems as a student are solved!

Reliable

Professional

Affordable

Quick

Using this writing service is legal and is not prohibited by any law, university or college policies. Services of Elite Academic Research are provided for research and study purposes only with the intent to help students improve their writing and academic experience. We do not condone or encourage cheating, academic dishonesty, or any form of plagiarism. Our original, plagiarism-free, zero-AI expert samples should only be used as references. It is your responsibility to cite any outside sources appropriately. This service will be useful for students looking for quick, reliable, and efficient online class-help on a variety of topics.