SecurityFocus HOME Infocus: Justifying the Expense of IDS, Part One: An Overv
Justifying the Expense of IDS, Part One: An Overview of ROIs for IDS
by David Kinn and Kevin Timm
last updated July 18, 2002
Introduction
A positive return on investment (ROI) of intrusion detection systems (IDS) is dependent upon an organization's deployment strategy and how well the successful implementation and management of the technology helps the organization achieve the tactical and strategic objectives it has established. For organizations interested in quantifying the IDS's value prior to deploying it, their investment decision will hinge on their ability to demonstrate a positive ROI. ROI has traditionally been difficult to quantify for network security devices, in part because it is difficult to calculate risk accurately due to the subjectivity involved with its quantification. Also, business-relevant statistics regarding security incidents are not always available for consideration in analyzing risk.