Base lining
• Organizations do not have any contact to each other
• No two organizations are identical to each other
• The best practices are a moving target
• Knowing that what was happening on in information security industry in the recent years through benchmarking does not necessarily prepare for what is next
Analysis of measures against the standards which are established. In information security, base lining is comparison of security activities and events against the future performance of organizations.
Other Feasibility Studies
Operational: examines how proposed information security alternatives will contribute to organization’s efficiency, and overall operation
Technical: examines whether or not organization has or can acquire technology required to implement and support the control alternatives
Political: defines what can or cannot happen based on consensus and relationships between the communities of interest