1. Define what the score represents
The model assigns weights to six fictional coverage units: baseline, privileged, shared, detection, restore and review. They are teaching preferences, not probabilities, euros of avoided loss or security percentages. A unit contributes once if at least one selected project covers it. This design makes a specific overlap visible without claiming to measure every relationship among real controls. In production, the team would need to establish that each capability exists, works and applies to the service. Before taking a score to a committee, explain where weights came from, who approved the criteria and what the number omits. An exact value can still arise from weak assumptions.
2. Compare standalone and incremental value
A covers privileged with weight 20 and shared with weight ten, producing 30 standalone points. B covers shared and detection with weights ten and 18, producing 28. Adding 30 and 28 counts shared twice. With M, A and B, the correct score in this model is 53: five for baseline, 20 for privileged, ten for shared and 18 for detection. Once A is selected, B adds 18 points rather than 28. This distinction helps ask whether additional cost delivers a new capability or duplicates an existing one. Overlapping controls can still provide defense-in-depth value; that needs an appropriate model and evidence rather than automatic addition.
3. Compare feasible combinations before choosing
The exercise enumerates all 32 subsets of five projects and finds ten meeting the reference conditions. Among them, M+B+C has the highest score, 59, using a budget of 75. M+A+B is also feasible but scores 53 while consuming all 80 available units. Always choosing the project with the highest standalone score does not guarantee the best combination. Likewise, selecting the cheapest project can leave a mandatory condition unmet. The program retains tied alternatives and uses cost, days and identifier only for deterministic presentation. That technical tie-break is not an approved business preference and does not remove the need to compare consequences absent from the input.
4. Find assumptions that change the decision
In the reference case, restore is worth 26 points. Reducing that weight to eight while retaining other conditions changes the preferred combination to M+A+B. When B’s cost rises from 25 to 40, M+B+C exceeds budget and another combination becomes preferred. These checks show sensitivity to those assumptions; they do not establish which scenario is more probable. To decide whether more information is worth collecting, ask whether a better estimate could change the choice and whether that change justifies analysis cost and delay. Keep versions of assumptions and results. Changing numbers solely to preserve the initial recommendation prevents learning from evidence.
5. Track delivery and realized benefits
After funding the portfolio, retain the business case as a hypothesis to verify. Installation, use, operating performance and business-objective effects are different observations. A detection project can deliver sensors without adequate critical-path coverage or available analysts. Record the benefit owner, measure, population, period, dependencies and acceptance criterion. If results fall short, investigate data and conditions before assigning causality to one tool. The lab only calculates combinations from synthetic data; it executes no controls and measures no avoided losses. For an APS handover, request operational evidence in the affected service and keep forecast benefit, delivered capability and observed outcome distinct.
# From content/labs/cism-investment-portfolio
from portfolio import fixture, solve
data = fixture
data["weights"]["restore"] = 8
print(solve(data)["best"])
# Preferred set changes to M+A+B under this new preference.
# This is sensitivity, not a probability or realized-loss estimate.
A+B sums to 58 standalone points but covers 48 unique points; including M brings the combination to 53. Changing the restore weight can change portfolio selection.
Common pitfalls
Adding overlapping benefits; treating points as money; hiding ties; confusing calculated selection with authorization or realized benefit.
Related topics: Security investment and operating capacity
Compare the combination’s incremental value and retain the connection among assumption, decision and observed outcome.
Reference: Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management · CISM current outline before November 3, 2026