Risk Management Framework for Approaching the ROI in Security

For designing cost-effective security strategies, organizations need practical and complete frameworks for security and risk management. This paper examines methods that can be used to measure and to manage risks within organizations. The main objective is to propose an extension of the regular risk management frameworks to the return on security investment approaches and forecasting techniques, as a way to reduce risks and improve results about uncertain situations for information security.
