Total annual security investment at the Medium tier — sum of Physical, Technical & Administrative controls.
Controls costed: 30
All controls below are derived from and mapped to the ISO/IEC 27002:2022 information security controls standard, organized into Physical, Administrative & Technical categories.
Physical0%
Administrative0%
Technical0%
Formulas, variables & how the total is built
Cost model. The total is the sum of every control at the selected security tier: Total = Physical + Technical + Administrative. Each control uses the project team's own equation. Nothing is scaled, marked up, or reduced beyond what the equations specify.
Variables.SF = square feet (physical controls scale by SF ÷ 25,000); N = number of employees, taken 1:1 with devices (per-user / per-device controls); H = hours spent on compliance tasks per year (hourly administrative controls). Some controls are flat annual amounts independent of size.
Security tier & range. Each control has a Low, Medium, and High figure; the selector applies that tier to every control at once. Uncheck any control to exclude it. The headline is shown as a ±10% range because this is a budgetary estimate, not a quote.
Disclaimer: Estimates are directional and based on the project team's cost equations; they are not vendor quotes or guarantees of actual pricing.
About
About CEISS
CEISS (Cost Estimation for Information Security Systems) is a planning tool that helps organizations forecast the annual investment required to build and maintain a mature security program. By entering a few basic parameters — facility size, employee count, and compliance hours — teams get a transparent, itemized cost breakdown across physical, administrative, and technical controls.
Every figure is derived from the project team's own cost equations, mapped directly to the ISO/IEC 27002:2022 controls standard. Nothing is marked up or hidden; the total is simply the sum of each selected control at your chosen security tier.
Why it matters
Security budgeting is often opaque and reactive. CEISS makes it structured and defensible, giving leadership a clear, standards-aligned starting point for planning, negotiation, and prioritization.
Solution
Our Solution
CEISS translates real-world organizational parameters into a defensible security budget. Our calculation engine systematically addresses physical real-estate parameters, active identity and device scopes, and administrative compliance effort — each modeled with its own equation.
How it works
Physical controls scale with facility square footage, technical controls scale with your employee/device count, and administrative controls scale with annual compliance hours or fixed program costs. A single security-level selector applies a Low, Medium, or High tier to every control at once, so you can compare build scenarios instantly.
What you get
An interactive dashboard with a headline budget range, per-category percentages, and the ability to toggle individual controls on or off to fit your scope and risk appetite.
Case Study
Case Study
A multi-site, highly regulated organization used CEISS to model its security investment across facilities of varying size and headcount. By layering the control matrix against ISO/IEC 27002 categories, the team was able to identify cost-optimization opportunities and right-size spending per site.
Outcome
The estimation pipeline surfaced where physical controls were over-provisioned relative to facility size and where technical controls needed to scale with device growth. Leadership used the transparent, tiered breakdown to reallocate budget and justify the program to stakeholders.
The result was a clearer, standards-aligned roadmap for security investment that could be revisited and adjusted as the organization grew.
Contact
Contact Us
Have a question about CEISS or want to discuss your organization's security budgeting needs? Send us a message and we'll get back to you.
Before You Continue
The CEISS dashboard provides budgetary estimates only. All figures are directional projections generated from the project team's cost equations and are intended for planning and educational purposes.
These numbers are not vendor quotes, contracts, or guarantees of actual pricing, and they do not constitute financial, legal, or professional security advice. Actual costs will vary based on your vendors, contracts, region, and specific requirements.
By continuing, you acknowledge that TAPSecure and the project team cannot be held liable for any decisions, expenditures, or outcomes based on the estimates provided by this tool. Please independently verify all figures before making any purchasing or budgeting decisions.