IDS mailing list archives

Re: Value of IDS, ROI


From: Vladimir Vuksan <vlists () veus hr>
Date: Tue, 03 May 2005 21:08:13 -0600

Jason Patel wrote:

I was wondering how big companies CIO show their executives Return of investment on IDS. What is the monitoring strategy for IDS alerts. I am trying to figure monitoring strategy and how to show my executive that how important job this is, but cant come up with a convincing solution. Anyhelp is highly appreciated.
I would think this would be an easy argument to make :-). The way I would look at it is to figure out how would separate types of incidents affect productivity in an organization. For example virus outbreak takes down whole network resulting in 100 employees losing 8 hours of productivity. If IDS was present there would be only 2 hours lost productivity. So with IDS there is 6 hours less lost productivity due to early alerting, containment etc. In money terms than you can come with a dollar figure e.g. 6 hours times 100 employees = $XXXX. You may be able to find what the average number of security incidents for organization of your size on the net.

Vladimir

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
--------------------------------------------------------------------------


Current thread: