Talk With an Expert

Gathering Security Metrics and Reaping the Rewards

Gathering Security Metrics and Reaping the Rewards (PDF, 2.14MB)Published: 16 Nov, 2009
Created by:
Dan Rathbun

This paper deals with the importance of using objective measurement to manage security improvements and to steer an information security program. It outlines the best way to design and produce a comprehensive security metrics program. It also describes how to leverage that effort within an organization to achieve improved decision-making, to increase visibility, to perform benchmark comparisons, and to demonstrate the value of the Information Security department.Far from being another treatise on detailed metric formulas or data analysis techniques, this is a practical roadmap for initiating a brand new metrics program or strengthening an existing one. We will discuss what security metrics are; the value they bring; what to measure; where to get the raw data; how to produce useful metrics and the importance of presenting them in a visually compelling and logically persuasive way. Without objective measurement leadership is nearly impossible, so join us as we consider the benefits of a well-designed security metrics program.