Defining Security Metrics
摘要
How do you know how well you are doing, unless you have metrics to tell you? Metrics provide decision support in running an organization. When an organization establishes a set of metrics, the organization can get a realistic baseline, or view, of how it performs at a point in time. Future metrics then determine whether performance improves with new controls. For security organizations, metrics are a way to regularly monitor how well security controls, the security organization, and the organization as a whole are performing relative to security goals. In fact, ISACA’s CISM Review Manual suggests: “Key controls that cannot be monitored pose an unacceptable risk and should be avoided” [p 194, 3]. This chapter reviews recommendations for metrics from the top-down, management perspective, as well as from technical recommendations.