RONSI: a framework for calculating return on network security investment

被引:1
|
作者
Barik, Kousik [1 ]
Misra, Sanjay [2 ]
Fernandez-Sanz, Luis [1 ]
Koyuncu, Murat [3 ]
机构
[1] Univ Alcala, Dept Comp Sci, Madrid, Spain
[2] Inst Energy Technol, Dept Appl Data Sci, Halden, Norway
[3] Atilim Univ, Dept Informat Syst Engn, Ankara, Turkiye
关键词
Return on network security investment (ROSI); Cyberattack; Network security; Bayesian approach; Investment decisions; ROSI;
D O I
10.1007/s11235-023-01039-9
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This competitive environment is rapidly driving technological modernization. Sophisticated cyber security attacks are expanding exponentially, inflicting reputation damage and financial and economic loss. Since security investments may take time to generate revenues, organizations need more time to convince top management to support them. Even though several ROSI techniques have been put out, they still need to address network-related infrastructure. By addressing gaps in existing techniques, this study delivers a comprehensive framework for calculating Return on Network Security Investment (RONSI). The proposed framework uses a statistical prediction model based on Bayes' theorem to calculate the RONSI. It is validated by Common Vulnerability Security Systems (CVSS) datasets and compared to existing studies. The results demonstrate that the annual loss is reduced to 75% with the proposed RONSI model after implementing a security strategy, and the proposed model is compared with existing studies. An organization can effectively justify investments in network-related infrastructure while enhancing its credibility and dependability in the cutthroat marketplace.
引用
收藏
页码:533 / 548
页数:16
相关论文
共 50 条
  • [21] Energy return on investment: Toward a consistent framework
    Mulder, Kenneth
    Hagens, Nathan John
    AMBIO, 2008, 37 (02) : 74 - 79
  • [22] Return on security investment against cyber attacks on availability
    Min, Byoung Joon
    Yoo, Seung Hwan
    Ryu, Jong Ho
    Seo, Dong Il
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 2, 2006, 3981 : 270 - 278
  • [23] Maximizzing return on security safeguard investment with constraint satisfaction
    Lee, Taek
    Kim, Dohoon
    In, Hoh Peter
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND ASSURANCE, 2008, : 172 - 175
  • [24] Return on security investment (ROSI) - A practical quantitative model
    Sonnenreich, W
    Albanese, J
    Stout, B
    JOURNAL OF RESEARCH AND PRACTICE IN INFORMATION TECHNOLOGY, 2006, 38 (01): : 45 - 56
  • [25] Network Security Framework
    Gupta, Kapil Kumar
    Nath, Baikunth
    Ramamohanarao, Kotagiri
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2006, 6 (7B): : 151 - 157
  • [26] A General Mathematical Framework for Calculating Systems-Scale Efficiency of Energy Extraction and Conversion: Energy Return on Investment (EROI) and Other Energy Return Ratios
    Brandt, Adam R.
    Dale, Michael
    ENERGIES, 2011, 4 (08): : 1211 - 1245
  • [27] CALCULATING THE RETURN ON INVESTMENT FOR IFN-FREE DAAS: THE CASE OF GREECE
    Drakos, K.
    Kakouros, M.
    Efthymiou, X.
    Anastasiou, D.
    VALUE IN HEALTH, 2017, 20 (09) : A783 - A783
  • [29] The energy return on investment of BECCS: is BECCS a threat to energy security?
    Fajardy, Mathilde
    Mac Dowell, Niall
    ENERGY & ENVIRONMENTAL SCIENCE, 2018, 11 (06) : 1581 - 1594
  • [30] Measuring Success: The Case for Calculating the Return on Investment of Environmental Public Health Tracking
    Charleston, Alex E.
    Banerjee, Anyana
    Carande-Kulis, Vilma G.
    JOURNAL OF PUBLIC HEALTH MANAGEMENT AND PRACTICE, 2008, 14 (06): : 600 - 604