This paper investigates if IT security is as a part of value creation. The first part of the commentary focuses on the current theoretical conditions for IT security as a part of value creation. Different Return On Security Investment (ROSI) models are studied to investigate if they can calculate value creation with regard either to efficiency or to effectiveness. The second part of the paper investigates empirical evidence of a ROSI or any indication of a shareholder value perspective on IT security in three large, listed companies from different business segments. What they have in common is their first priority: value creation. The commentary begins by describing the "Productivity Paradox". It is followed by the most well-known ROSI models. Then, it explains the models applicability in value creation. Next, the three companies in the study are investigated. In the following section conclusions are drawn. Finally, the results of the research are discussed. © 2007 International Federation for Information Processing.
CITATION STYLE
Magnusson, C., Molvidsson, J., & Zetterqvist, S. (2007). Value creation and return on security investments (ROSI). In IFIP International Federation for Information Processing (Vol. 232, pp. 25–35). https://doi.org/10.1007/978-0-387-72367-9_3
Mendeley helps you to discover research relevant for your work.