Abstract | In this paper we reviewed the cost-benefit analysis of Information Security and applied to Organisations Responsible for Vulnerable Individuals (ORVIs). Our research investigates the mitigation value and cost effectiveness of mitigation methods which discussed findings based on business focus and evaluation. Research findings indicated metrics for calculations assumptions, as proposed in the research work and thus, determined that the relative data analysis presented for cost comparable scores of the mitigation methods adopted. It is recommended from our analysis that ORVIs implement Internal Penetration Testing alongside Policy implementation due to the added benefit this combination has for this specific use-case. |
---|