Return on Investment for Information Security

In any event, experiment shows that the bottom line result from the ROSI tool is not much affected by setting the frequency for Negligible likelihood to either 0.05 or 0.00. Individual security incidents probably occur over time according to a Poisson distribution, and their corresponding frequencies would not be uniformly distributed. ................