Journal of Information System Security
Volume 1, Number 2 (2005)
Pages 325
ISSN 1551-0123
Sriraman Ramachandran — The University of Texas at San Antonio, USA
Greg B. White — The University of Texas at San Antonio, USA
Information Institute Publishing, Washington DC, USA




Investments in Information Technology Security Tools and Products (ITSTP) create both tangible benefits such as increased server availability time as well as intangible benefits such as increased protection and increased customer confidence and trust. Existing estimators such as Annual Loss Expectancy (ALE) and Cost Benefit Analysis (CBA) have been widely used to quantitatively perform risk analysis and to identify tangible benefits from investments in IT-STPs. Intangible benefits from IT-STPs, which are as critical as tangible benefits, are harder to measure. The lack of metrics for assessing these intangibles provides a challenge for comprehensively assessing the value of investment in IT-STPs. This paper explores past IT payoff literature to develop a comprehensive methodology for assessing the impact of IT-STPs, which can better assess both the tangible and intangible benefits. In this light, we present a Complementarity Based First-Order Effects (CoBFOE) approach to assess the impact of investments in IT-STPs based on Barua et al.’s (1995) Business Value Complementarity (BVC) model. An illustration of how the CoBFOE approach could be used in an organizational setting is also discussed.




Security Investment, Tangible and Intangible Benefits, Complementarity Based First-Order Effects




