topleft
topright
Enter the Member Network Zone View the Top 10 Points Leaderboard View Members Who Are Currently Online View Latest Member Activity

Featured Members


Member Network Zone

Expert Blog Comments

IT Worker Confidence Grows
Our lives revolve around technology and this does not surprise me. Good news!
Is Your Team Working Through Lunch?
Brilliant: this should be ENFORCED in all companies struggling to be social! Great read : bookmarked...
What Makes a Great Team Member?
This is so true! Our project management team, and some other people I know fit this description pe...
How to Valuate Your Information Assets Print E-mail
Share This -
Digg
Delicious
Slashdot
Furl it!
Reddit
Spurl
Technorati
YahooMyWeb
Thursday, 14 January 2010

By Danny Lieberman, Software Associates

A client recently asked: How do I assign a dollar value to information assets? … Should I use the purchase value of the asset, replacement value or expected damage to the company if the asset were stolen or exploited?

Estimating asset value is without doubt the most frequent question we get when it comes to calculating data security risk in monetary terms. There are several practical guidelines for measuring information assets value:

Use the Right Metric

A common mistake made by marketeers who work for data security vendors is to estimate the cost of a data security breach as the number of records multiplied by some plug number. The cost of a data security breach to a company is not the same as the cost of a customer data record breach to a customer.

A customer may not even know that her credit card number is breached (considering that 250 million credit card numbers have been stolen in the past few years, it is a reasonable assumption that your credit card number is known to someone who stole) but your cost is zero, isn’t it?

Ask an Expert

Usually the CFO. The expert can and should provide confidence intervals for his estimate. The CFO is the best source and best equipped to decide if replacement value, purchase value/depreciated or opportunity cost is the relevant metric to measure the value of an asset.

It’s ok if your CFO says that company IP is worth $50 million with a confidence level of 85 percent.

If you do a practical threat modeling exercise, you will be able to test sensitivity of your threat model to the confidence boundaries.

Use Test Equipment

For example, if the cost of acquiring a customer is $50, you can write a sql query to find out how many customers you have and then multiply by $50.

Looking at the fixed assets and GL modules is an example of using test equipment. If you have to measure the number of credit cards in clear text circulating on your network, I suggest network surveillance.

Use Random Sampling From a Population of Asset Value Estimators

The Rule of Five says that there is a 93 percent chance that the median of a population is between the smallest and largest values in any random sample of the population. So, if you have to estimate value of a digital asset like intellectual property, you can ask five people for their estimate. For example, the CFO, the CTO, a customer, your VP marketing and a software developer who worked for one of your competitors.

Measure in Small Increments and Be Prepared to Iterate

In other words, when you do a threat model exercise, take small steps -- measure 5-10 asset values and move on from there.

Most of the information value is gained at the beginning of a measurement exercise and most companies measure things that have zero information value to the business because they are easy to measure (for example, how many SSH password attacks were made on company web servers) instead of the important things, like what is the value of a field service engineer diagnostic database that is distributed to notebook computers.

Copyright © 2008 To Present · Information-Security-Resources.com

Danny Lieberman is security expert and founder of Software Associates.




Comment on this article
RSS comments

Only registered users can write comments.
Please login or register.

 
Share This -
Digg
Delicious
Slashdot
Furl it!
Reddit
Spurl
Technorati
YahooMyWeb
< Previous   Next >




Vendor Zones

Visit the Cisco Video Zone

News & Noteworthy Archive

Past News Items From Reuters

White Paper Library

Copyright © 2007-2012 CIOZones. All Rights Reserved. CIOZone is a property of PSN, Inc.