Performing a Cost-Benefit Analysis on the Identified Risk Elements

A cost-benefit analysis (CBA) helps determine whether a countermeasure should be used. If the benefits of a countermeasure are more than the costs, the countermeasure provides benefits, whereas, if the benefits of the countermeasure are less than the cost of the countermeasure, the countermeasure does not provide benefits.

If two possible countermeasures that will mitigate the same risk are available, two CBAs can be completed to determine which one provides the better benefits. That countermeasure can then be implemented.

NOTE

If the turnaround between approval of the risk ...

Get Managing Risk in Information Systems, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.