Building the business case #6
Arguably, the most important part of your business case is being able to clearly communicate the costs and benefits of a program. Below is a suggestion for this final part of your business case.Cost Benefit Analysis
Costs:
To fulfill the required mandate for a security awareness training program, we will need to allocate resources and purchase materials for this purpose. To ensure the program’s success on a long-term basis, we are requesting that a Security Awareness Training Manager be appointed to this program. Expenses will include this individual’s salary as well as the costs for developing and/or delivering the awareness program.Cost estimates are summarized in the table below
| Item | Estimate |
| Program Manager Salary (estimate ramp up time, benefits, etc.) | |
| Commercial of the Shelf Online Training Program License Costs (1 year + additional subsequent years if applicable) | |
| Customization costs for online program (costs for tweaking the content to meet the company's branding/wording as well as any policy links) | |
| Learning Management System – rental or purchase costs and comparison if required | |
| Promotional materials for communicating the awareness program (ie., posters, games, videos) | |
| Additional staff that might be required from time to time for delivery of program (i.e., IT Admin assistance for technical requirements, HR staff for approval and review of content) |
Benefits:
Our proposed information security awareness program will realize the following benefits:
- Make employees aware and communicate more effectively internal security policies and procedures.
- Create a culture of security awareness by providing both the motivation and an understanding of the risks and threats and how to mitigate them.
- Reduce the number of threats and potential risks and safeguard important company information.
- Comply with federal/state regulations on security policies and practices.
- Provides a basis from which disciplinary and/or legal action can be facilitated.
- Reduce the risk and cost of breaches.

Comments
Post new comment