Many believe that complete security is infeasible. Therefore, we are left with incomplete security. Generally, the greater the security, the greater the cost. Discuss how one should weigh the benefits and associated costs of security.
First, it is important to identify what needs to be protected and at what levels. Conducting a risk analysis in addition to a business impact analysis will help to identify both the current state and desired state as well as the acceptable thresholds of impact. A security improvement plan can then be established using the gathered data. Finally, a cost-benefit analysis can be performed on the security solutions.