1. Start with the business decision
A fictional fund-services team receives proposals to improve privileged access, detection and recovery. Each supplier presents a favorable score, but the projects compete for the same APS engineers. The committee needs to decide which combination to fund, under which conditions and with what exposure while other work waits. Before ranking proposals, make service objectives, acceptance criteria and constraints explicit. An applicable obligation does not disappear because another proposal has a better estimated return. Determining applicability and handling potential noncompliance belong to the appropriate governance process. In the exercise, M is mandatory by teaching assumption: the program never removes it to improve another alternative’s score.
2. Compare costs on the same basis
A proposal costing 40 units for acquisition can exceed another costing 55 once integration, testing, operations, learning and exit are included. Record the horizon, cost categories and exclusions before comparing totals. Distinguish amounts already paid from future spending the decision can still change. A project with substantial sunk costs may merit continuation because of future benefits, but not simply because money was spent. In the lab, cost represents synthetic budget units over a common horizon; deliveryDays and runDays are separate constraints. A benefit score is not added to euros, and a three-year cost is not compared directly with an annual avoided-loss estimate.
3. Treat operations as a real constraint
The reference plan has a budget of 80, ten available implementation days and eight operating days within the defined recurring period. The M, B and C combination uses 75, ten and seven respectively. It fits those limits but leaves no implementation slack. If incidents reduce availability to eight days, that combination becomes infeasible even with sufficient money. If operating availability falls to five days, it is again infeasible. The exercise finds a different combination in each case. These totals do not establish that people have the required skills, can work on the necessary dates or provide weekend coverage. Those conditions need their own planning and validation.
4. Fund dependencies and recognize infeasibility
Every discretionary initiative in the lab depends on M. Selecting A without M produces an infeasibility reason; the program does not silently create resources to repair the omission. When several initiatives depend on M, its cost appears once in the selected combination. However, a funded prerequisite is not necessarily operational before dependent projects need it. The model does not calculate a schedule. If budget falls to 19 while M costs 20, no feasible solution exists under the supplied conditions. The report should request a decision about resources, scope or an authorized way to meet the need, explaining exposure. Hiding M or inventing savings merely to present a green list would destroy the constraint’s meaning.
5. Deliver a usable business case
For the sponsor, prepare a comparison containing the protected objective, alternative, future costs, capacity, dependencies, assumptions, residual exposure and requested decision. Identify who confirms each estimate and who accepts operational commitments. Remaining budget is not an obligation to spend: another project can introduce work that operations cannot sustain. Funding can be staged against observable criteria, such as demonstrating integration and operational response in a pilot before expansion. Define in advance what leads to continuation, correction or stopping. The security manager recommends and presents consequences; neither the model nor its score grants authority to approve spending or accept risk.
# From content/labs/cism-investment-portfolio
# Run all checks: python3 run.py --output evidence-local.json
from portfolio import fixture, evaluate, solve
data = fixture
print(evaluate(data, ["M", "A", "B"]))
print(solve(data)["best"])
# Cost 80 / score 53 for M+A+B; best is M+B+C with score 59.
M+B+C fits within 80 units and uses ten implementation days. With only eight days available, the combination must be reconsidered even if budget is unchanged.
Common pitfalls
Comparing licenses alone; confusing budget with capacity; funding dependencies without a schedule; omitting mandatory work to make a proposal feasible.
Related topics: Portfolio benefits and sensitivity analysis
A proposal supports a decision only when it makes costs, dependencies and capacity to sustain the outcome explicit.
Reference: Prioritizing Cybersecurity Risk for Enterprise Risk Management · CISM current outline before November 3, 2026