3.3 ANSI/ASIS Standards & Return on Security Investment (ROSI)

Key Takeaways

  • ANSI/ASIS standards such as PSC.1-2012, SPC.1-2009, and the ESRM Guideline establish globally recognized benchmarks for security governance and resilience.
  • Return on Security Investment (ROSI) quantifies financial impact using the formula: ROSI = [(Risk Mitigated × Monetary Impact) - Solution Cost] / Solution Cost.
  • Enterprise Security Risk Management (ESRM) establishes that business asset owners own the risk, while security professionals act as strategic advisors.
  • Demonstrating security value to executive leadership requires articulating cost avoidance, operational efficiency, loss reduction, and strategic alignment.
Last updated: July 2026

ANSI/ASIS Standards & Return on Security Investment (ROSI)

Security management has evolved from an ad-hoc operational function into a formalized, standards-based management discipline. Security professionals must align organizational security programs with recognized industry standards while demonstrating tangible financial value to executive leadership and the Board of Directors. This section addresses key ANSI/ASIS standards, the mathematical calculation of Return on Security Investment (ROSI), and techniques for communicating security value to the C-suite.


Key ANSI/ASIS Standards

ASIS International, accredited as a standards-developing organization by the American National Standards Institute (ANSI), produces globally recognized standards and guidelines that establish best practices across the security domain.

ANSI/ASIS StandardTitle / Focus AreaKey Objectives & Applications
ANSI/ASIS PSC.1-2012Quality Management System for Private Security Company OperationsEstablishes governance frameworks for private security companies (PSCs) operating in high-risk environments. Integrates international human rights law, accountability, legal compliance, and risk management based on the Montreux Document and International Code of Conduct (ICoC).
ANSI/ASIS SPC.1-2009Organizational Resilience: Security, Preparedness, and Continuity Management SystemsProvides a comprehensive framework for organizations to anticipate, prevent, prepare for, respond to, and recover from disruptive incidents. Integrates physical security, business continuity, and crisis management into a unified resilience architecture.
ANSI/ASIS ESRM Guideline (2019)Enterprise Security Risk Management (ESRM)Defines a strategic security management philosophy where security risks are evaluated and managed holistically within the context of overall enterprise business objectives. Establishes that business asset owners own the risk, while security professionals serve as expert advisors.

Return on Security Investment (ROSI)

Historically viewed purely as a cost center, modern security operations are increasingly evaluated on financial performance metrics. Return on Security Investment (ROSI) is a quantitative metric used to justify security expenditures by calculating the financial return generated through risk reduction.

The ROSI Formula

ROSI=(Risk Mitigated×Monetary Impact)Cost of SolutionCost of Solution\text{ROSI} = \frac{(\text{Risk Mitigated} \times \text{Monetary Impact}) - \text{Cost of Solution}}{\text{Cost of Solution}}

Alternatively, ROSI can be expressed using Annualized Loss Expectancy (ALE):

ROSI=(ALEpriorALEpost)Cost of SolutionCost of Solution\text{ROSI} = \frac{(\text{ALE}_{\text{prior}} - \text{ALE}_{\text{post}}) - \text{Cost of Solution}}{\text{Cost of Solution}}

Where:

  • $\text{ALE}_{\text{prior}}$ = Baseline expected annual financial loss without the security control.
  • $\text{ALE}_{\text{post}}$ = Residual expected annual financial loss after implementing the security control.
  • $(\text{ALE}{\text{prior}} - \text{ALE}{\text{post}})$ = Total risk mitigated (annual financial savings).
  • $\text{Cost of Solution}$ = Total annual expenditure to acquire, deploy, operate, and maintain the security control.

Step-by-Step ROSI Calculation Example

Imagine a distribution facility that experiences cargo theft resulting in an Annualized Loss Expectancy ($\text{ALE}_{\text{prior}}$) of $300,000. The security manager proposes installing an integrated CCTV and access control system with 24/7 video monitoring.

  1. Calculate Cost of Solution:
    • Equipment acquisition, installation, and annual monitoring maintenance total $60,000 per year.
  2. Estimate Risk Reduction:
    • The security system is estimated to reduce cargo theft by 80%.
    • Residual Loss ($\text{ALE}_{\text{post}}$) = $$300,000 \times (1 - 0.80) = $60,000$.
    • Financial Risk Mitigated = $$300,000 - $60,000 = $240,000$.
  3. Calculate ROSI:

ROSI=$240,000$60,000$60,000=$180,000$60,000=3.0(300%)\text{ROSI} = \frac{\$240,000 - \$60,000}{\$60,000} = \frac{\$180,000}{\$60,000} = 3.0 \quad (300\%)

A ROSI of 300% indicates that for every dollar invested in the security system, the organization recovers its initial cost plus an additional $3.00 in avoided losses.


Enterprise Security Risk Management (ESRM) Governance

The ANSI/ASIS ESRM Guideline introduces a fundamental shift in corporate governance. In traditional security models, security managers often acted as "gatekeepers" who unilaterally decided acceptable risk levels. Under ESRM, security governance follows a collaborative cycle:

  ┌─────────────────────────────────────────────────────────────────┐
  │                 ESRM Lifecycle Architecture                     │
  └────────────────────────────────┬────────────────────────────────┘
                                   │
  ┌──────────────────┬─────────────┴─────────────┬──────────────────┐
  ▼                  ▼                           ▼                  ▼
┌──────────────┐   ┌──────────────┐           ┌──────────────┐   ┌──────────────┐
│ Identify &   │   │ Assess Risks │           │ Respond to   │   │ Continuous   │
│ Prioritize   │──>│ to Assets    │──────────>│ Risks        │──>│ Monitoring & │
│ Assets       │   │ (T×V×C)      │           │ (Mitigate)   │   │ Improvement  │
└──────────────┘   └──────────────┘           └──────────────┘   └──────────────┘

Roles and Responsibilities in ESRM

  • The Business Asset Owner: The executive or operational business unit leader who owns the business process or physical/information asset. Under ESRM, the asset owner holds ultimate accountability for accepting, mitigating, transferring, or avoiding security risks.
  • The Security Professional: Serves as a subject matter expert, facilitator, and trusted advisor. The security professional identifies threats, conducts risk evaluations, recommends cost-effective countermeasures, and presents findings to asset owners to support informed decision-making.

Demonstrating Value to the C-Suite

Executive leadership evaluates operational departments based on strategic alignment, risk management, and financial impact. Security leaders must translate security metrics into executive business language.

       ┌────────────────────────────────────────────────────────┐
       │             Demonstrating C-Suite Value                │
       └───────────────────────────┬────────────────────────────┘
                                   │
  ┌─────────────────┬──────────────┴──────────────┬─────────────────┐
  ▼                 ▼                             ▼                 ▼
┌──────────────┐  ┌──────────────┐             ┌──────────────┐  ┌──────────────┐
│     Cost     │  │ Loss & Shrink│             │ Operational  │  │  Strategic   │
│  Avoidance   │  │  Reduction   │             │ Efficiency   │  │  Alignment   │
└──────────────┘  └──────────────┘             └──────────────┘  └──────────────┘
  1. Cost Avoidance: Quantifying potential costs prevented through proactive security measures, including avoiding regulatory fines (e.g., OSHA, GDPR, HIPAA), litigation expenses from negligent security lawsuits, and brand damage remediation.
  2. Loss and Shrinkage Reduction: Direct reduction in tangible inventory losses, intellectual property exfiltration, and operational downtime caused by security breaches.
  3. Operational Efficiency: Leveraging security technology investments to streamline general business operations—such as utilizing smart access control analytics for space utilization planning or integrating thermal cameras for machinery safety monitoring.
  4. Strategic Business Alignment: Positioning security as a business enabler that opens new revenue channels—such as obtaining security certifications (e.g., ISO 27001 or ANSI/ASIS PSC.1) required to win major enterprise or government contracts.
Test Your Knowledge

A security manager calculates that installing an automated access control system reduces expected annual loss from inventory theft from $200,000 to $40,000. The solution costs $50,000 annually to implement and maintain. What is the Return on Security Investment (ROSI)?

A
B
C
D
Test Your Knowledge

Which ANSI/ASIS standard provides a comprehensive management system framework for private security companies, specifically incorporating international human rights standards and operational governance?

A
B
C
D
Test Your Knowledge

In Enterprise Security Risk Management (ESRM), who holds ultimate accountability for making risk treatment decisions (accept, mitigate, transfer, avoid) regarding operational assets?

A
B
C
D