My take is: A security initiative is the result of a risk assessment. E.g., the security initiative could mean the implementation of a SIEM as a mitigating control. Therefore, a risk assessment is given already.
To decide whether certain controls should be implemented, a cost-benefit analysis must be done. If costs outweigh benefits, there is no need to write a business case. If benefits outweigh costs, the cost-benefit analysis will be part of the business case later on.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Josef4CISM
1 month, 1 week agoServerBrain
4 months, 1 week ago