2009Unpublished venueRequires access

Managing Security Projects: Proposition of a Cost Model

Moufida Sadok

Open publisher page 0 citations

Abstract

Security project management must take into consideration the business requirements of the enterprise, the extension and complexity of its networked information system and the evolution of attack techniques. The efficiency of such project presumes a thorough cost-benefit analysis of the structure and dynamics of the IT components as well as the assessment of human and organisational parameters. Managers are more and more concerned with how security costs are planned, monitored and controlled. To this end, managers need a cost model including cost representation and risk parameters and capable of adapting company operational procedures, resource management, and corporate strategy to the evolution of digital risk. However, we have noticed a lack of security cost models in the project management literature. Only cost factors related to the technical task of security project have been addressed. This paper discusses the limits of the available technical cost models and proposes additional cost parameters including organizational, human and managerial aspects that must be considered and assessed in order to provide a more accurate estimation of security project cost. Our attempt is to provide two general cost models integrating these parameters. To conduct an accurate estimation of the involved parameters, a methodology is described based on expert intervention and decision making. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.

About this research paper

What this paper is about

Security project management must take into consideration the business requirements of the enterprise, the extension and complexity of its networked information system and the evolution of attack techniques. The efficiency of such project presumes a thorough cost-benefit analysis of the structure and dynamics of the IT components as well as the assessment of human and organisational parameters. Managers are more and more concerned with how security costs are planned, monitored and controlled. To this end, managers need a cost model including cost representation and risk parameters and capable of adapting company operational procedures, resource management, and corporate strategy to the evolution of digital risk. However, we have noticed a lack of security cost models in the project management literature. Only cost factors related to the technical task of security project have been addressed. This paper discusses the limits of the available technical cost models and proposes additional cost parameters including organizational, human and managerial aspects that must be considered and assessed in order to provide a more accurate estimation of security project cost. Our attempt is to provide two general cost models integrating these parameters. To conduct an accurate estimation of the involved parameters, a methodology is described based on expert intervention and decision making. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security project management must take into consideration the business requirements of the enterprise, the extension and complexity of its networked information system and the evolution of attack techniques. The efficiency of such project presumes a thorough cost-benefit analysis of the structure and dynamics of the IT components as well as the assessment of human and organisational parameters. Managers are more and more concerned with how security costs are planned, monitored and controlled. To this end, managers need a cost model including cost representation and risk parameters and capable of adapting company operational procedures, resource management, and corporate strategy to the evolution of digital risk. However, we have noticed a lack of security cost models in the project management literature. Only cost factors related to the technical task of security project have been addressed. This paper discusses the limits of the available technical cost models and proposes additional cost parameters including organizational, human and managerial aspects that must be considered and assessed in order to provide a more accurate estimation of security project cost. Our attempt is to provide two general cost models integrating these parameters. To conduct an accurate estimation of the involved parameters, a methodology is described based on expert intervention and decision making. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.

Key concepts: Risk analysis (engineering), Cost engineering, Computer science, Cost estimate, Basis of estimate, Process (computing), Cost contingency, Project management

Related papers

Back to paper searchBrowse research topicsOriginal source
Managing Security Projects: Proposition of a Cost Model — Research Paper | ScholarLens