Trends Report

Measure Information Security Effectiveness — Information Security Economics 103

Analyze Where You Spend Your Money Using The Three R's: Readiness, Response, And Recovery

September 26th, 2013
Ed Ferrara, null
Ed Ferrara
With contributors:
Christopher McClean , Thayer Frechette

Summary

This is the third in a series of reports providing new methods and guidance for the financial management of information security. For many companies, security spending and budgeting is a restatement of what was spent last year and is often represented as a percentage of total IT spending. Most organizations would benefit from a more practical method of budgeting that segments security spending into one of the three R's: readiness, response, and recovery. Doing this more accurately categorizes security spending and can help security and risk (S&R) pros allocate security resources more accurately and efficiently. For example, if a security team spends the correct amount of resources on readiness, the resources needed for response and recovery should be commensurably lower. This report explains how measuring the changes in spending for these three categories can help determine the effectiveness of your security program.

Want to read the full report?

Contact us to become a client

This report is available for individual purchase ($1495).

Forrester helps business and technology leaders use customer obsession to accelerate growth. That means empowering you to put the customer at the center of everything you do: your leadership strategy, and operations. Becoming a customer-obsessed organization requires change — it requires being bold. We give business and technology leaders the confidence to put bold into action, shaping and guiding how to navigate today's unprecedented change in order to succeed.