
- •Final report
- •I. Executive Summary II. Recommendations
- •1.1 Operational Environment and System Configuration
- •1.1.1 The Risk Assessment Team
- •1.1.2 Organization Details of SpecOrg
- •1.1.3 Physical Plant and Physical Security
- •1.1.4 System Configuration
- •1.2 Terms and Definitions
- •Introduction 13
- •1.3 Risk Analysis Methodology
- •1.4 RiskWatch Parameters and Data Analysis
- •I. Executive Summary
- •Executive Summary 2
- •2.1 Summary of asset categories
- •2.2 Assets within category
- •II. Recommendations
- •5.2.1 Physical Access Control
- •5.2.4 Contract Specifications
- •5.2.7 Life Cycle Management
- •5.2.9 Personnel Clearances
- •5.2.12 Risk Analysis
- •5.1 Summary of safeguards
- •Initial costs
- •5 Others (16.0%)
5.1 Summary of safeguards
The tables below show information about each of the safeguards considered by RiskWatch. It is sorted on the basis of the annualized Rate of Return on Investment (ROI) using Discount Rate of 10%.
The twelve numeric columns are, respectively,
the lifetime of the safeguard in years (Lifetime)
the initial cost (Initial Cost)
the annual maintenance cost (Maint. Cost)
the Basic Ratio of Total Benefits to Total Costs for Discount Rate 5% (B/C-5%)
the Annualized ROI with Discount Rate 5% (RoI-5%)
the Pay-back Period with Discount Rate 5% (PP-5%)
the Basic Ratio of Total Benefits to Total Costs for Discount Rate 10% (B/C-10%)
the Annualized ROI with Discount Rate 10% (RoI-10%)
the Pay-back Period with Discount Rate 10% (PP-10%)
the Basic Ratio of Total Benefits to Total Costs for Discount Rate 15% (B/C-15%)
the Annualized ROI with Discount Rate 15% (RoI-15%) 12. the Pay-back Period with Discount Rate 15% (PP-15%).
-
Safeguards
Lifetime
Initial Cost
Maint. Cost
Application Controls
3
$50,000.
$50,000.
Security Policy
3
$70,000.
$40,000.
Data Encryption
5
$500,000.
$500,000.
Personnel Clearances
1
$50,000.
$100,000.
Risk Analysis
3
$100,000.
$30,000.
Physical Access Control
3
$2,000,000.
$500,000.
Detection System
3
$1,000,000.
$200,000.
Quality Assurance
5
$400,000.
$300,000.
Classification Markings
3
$500,000.
$50,000.
Life Cycle Management
1
$200,000.
$0.
Personnel Control
3
$200,000.
$100,000.
Passwords/Authenticaion
5
$40,000.
$200,000.
Contract Specifications
1
$50,000.
$100,000.
-
Safeguards
B/C-5%
ROI-5%
PP-5%
Application Controls
10.11
3.37
1
Security Policy
5.30
1.77
1
Data Encryption
5.09
1.02
1
Personnel Clearances
0.17
0.17
0
Risk Analysis
0.20
0.07
0
Physical Access Control
0.03
0.01
0
Detection System
0.03
0.01
0
Quality Assurance
0.02
0.00
0
Classification Markings
0.01
0.00
0
Life Cycle Management
0.00
0.00
0
Personnel Control
0.00
0.00
0
Passwords/Authenticaion
0.00
0.00
0
Contract Specifications
0.00
0.00
0
Safeguards
B/C-10%
ROI-10%
PP-10%
Application Controls
10.11
3.37
1
Security Policy
5.25
1.75
1
Data Encryption
5.09
1.02
1
Personnel Clearances
0.17
0.17
0
Risk Analysis
0.19
0.06
0
Physical Access Control
0.03
0.01
0
Detection System
0.03
0.01
0
Quality Assurance
0.02
0.00
0
Classification Markings
0.01
0.00
0
Life Cycle Management
0.00
0.00
0
Personnel Control
0.00
0.00
0
Passwords/Authenticaion
0.00
0.00
0
Contract Specifications
0.00
0.00
0
Safeguards
B/C-15%
ROI-15%
PP-15%
Application Controls 10.11 3.37 1
Security Policy 5.20 1.73 1
Data Encryption 5.09 1.02 1
Personnel Clearances 0.17 0.17 0
Risk Analysis 0.19 0.06 0
Physical Access Control 0.03 0.01 0
Detection System 0.03 0.01 0
Quality Assurance 0.02 0.00 0
Classification Markings 0.01 0.00 0
Life Cycle Management 0.00 0.00 0
Personnel Control 0.00 0.00 0
Passwords/Authenticaion 0.00 0.00 0
Contract Specifications 0.00 0.00 0
The following table shows the safeguards with the 10 greatest Return on Investment (ROI-10%). Also shown are the Initial and Maintenance Costs of those safeguards. Following the table are barcharts and piecharts of the costs.
-
Safeguards
ROI-10%
Initial Cost
Maint. Cost
Application Controls
3.37
$50,000.
$50,000.
Security Policy
1.75
$70,000.
$40,000.
Data Encryption
1.02
$500,000.
$500,000.
Personnel Clearances
0.17
$50,000.
$100,000.
Risk Analysis
0.06
$100,000.
$30,000.
Physical Access Control
0.01
$2,000,000.
$500,000.
Detection System
0.01
$1,000,000.
$200,000.
Quality Assurance
0.00
$400,000.
$300,000.
Classification Markings
0.00
$500,000.
$50,000.
Life Cycle Management
0.00
$200,000.
$0.