...analysis must be performed for information security related projects and that this analysis should be subjected to externalreview from non-IT personnel. Projects will gain a lot of credbility from being described in terms that demonstrate their...
http://www.computerweekly.com/blogs/stuart_king/2007/10/roi-of-ips.html