Milliman Security Management System MS2 Home | Contact | Site Map | Milliman    
Milliman Security Management System
Overview
MS2
MS2:VM
 

Compliance FAQs

 

Does MS2 calculate a Return of Investment (ROI) for the security gaps identified during the risk and gap assessment?

 

Like any other profession, there are a range of theories and methodologies incorporated into the work of IT security professionals. Calculating an ROI for security gaps provides one such an example. The NIST SP 800-30 and other standards do not require ROI calculations to determine which security safeguard to implement or to prioritize which controls to implement first, although some security professionals consider such estimates useful.

 

MS2 calculates risk based upon a baseline set of information processing threats and the resulting likelihood and impact of these vulnerabilities. The results are factored by existing and planned security safeguards within an organization. Milliman chose not to include the value of the assets as the major determining factor or driver in deciding which security control to implement. The reasons for this include:

  • Assigning a monetary value to an information or computer asset such as a server or data can be very subjective.
  • Quantifying ROI or using asset valuation as a basis for the prioritization of control recommendations can lead to skewed and potentially undesirable results.  For example, there may be some generally accepted security controls that show a relatively low ROI for a specific organization.
  • Calculating ROI can be complex and resource-intensive relative to the impact that it can have on determining to implement a specific control. For example, the long-term public relations consequences of an identity theft breech or compliance violation may outweigh any short-term and measurable monetary loss.
  • Finally, many debate whether security controls result in any ROI. Security control implementation is fundamentally a risk-based decision, driven by an organization's desire to minimize a financial, operational, or regulatory exposure to a peculiar threat and vulnerability.
Therefore, organizations may determine the resources allocated for security by the cost of the safeguards within the overall context of risk and exposure given financial and business circumstances (i.e., the likelihood of vulnerability and its impact based upon the financial situation of the organization). MS2 quantifies the overall vulnerability risk impact of a specific security need to help guide such a security resource allocation process.  It also provides tools to aid an organization for documenting its rationales when it chooses not to implement a specific safeguard.

 

 

 

 

 

 

 

 

Compliance FAQs

How does MS2 help implement and maintain an effective security compliance program?


How does MS2 help ensure that the proper security safeguards are in place?


How does MS2 help your organization comply with Sarbanes-Oxley?


How does MS2 help with Gramm-Leach-Bliley Act (GLBA) compliance?


Are all the elements of the GLBA Safeguard Rule included in MS2?


What kind of security risk assessment methodology does MS2 use and does it conform to NIST (National Institute of Standards) protocols?


Why does MS2 map controls to standards such as NIST and ISO?


What is the ISO 17799 standard, and why is it so important?


Does MS2 calculate a Return of Investment (ROI) for the security gaps identified during the risk and gap assessment?


How does MS2 help achieve HIPAA compliance?


Which features in MS2 help organizations achieve HIPAA Security compliance?


What is the definition of common control?

 

If my vendor says that the system we are using is HIPAA Security compliant, does that mean we are also HIPAA Security compliant?