Reading my colleague’s Stuart King’s blog posting on the financial impact of security incidents reminded me of the continuing obsession that many parts of industry and academia still seem to have for achieving the Holy Grail of perfect ROI measurement. Many of them miss the point.
http://www.computerweekly.com/blogs/david_lacey/governance-issues/