Standards
Measuring cost is easy, but how often can organisations claim to measure risk? To accurately demonstrate the effectiveness of an IT security implementation, organisations need to measure risk continuously over time. There is a need to be able to compare risk today with last week, last month, last quarter or last year. By comparing risk trends against security spend those business executives will be able to better understand how their money has been spent. Not only that, but when the next budget request comes, they can be sure that they will see a measurable return on that investment.