
| Characteristic | Share of respondents |
|---|---|
| Assessments performed by internal audit function | 68% |
| Internal self-assessments by IR or information security function | 64% |
| Assessment by external party | 56% |
| Monitoring and evaluation of security incidents and events | 48% |
| In conjunction with the external financial statement audit | 35% |
| Benchmarking against peers/competition | 27% |
| Evaluation of information security operational performance | 19% |
| Formal certification to external security standards (e.g. ISO/IEC 27001:2005) | 15% |
| Formal certification to industry security standards (e.g. Payment Card Industry Data Security Standards) | 15% |
| Evaluation of information security costs | 14% |
| Evaluation of return of investment (or similar such ROSI) performance | 5% |
| No assessments performed | 4% |
The chart is not accessible to screen readers. Please switch to the table view to access the data.
Loading statistic...
Download
Source
Release date
November 2012
Region
Worldwide
Survey time period
May to July 2012
Number of respondents
1,836*
Special properties
CIOs, CISOs, CFOs, CEOs and other information security executives
Method of interview
Face-to-face interview, online survey
Supplementary notes
* Ernst & Young received feedback from nearly 1,836 CIOs, CISOs, CFOs, CEOs and other information security executives from 64 countries and across all industry sectors.
Citation formats





