Talk With an Expert

Measuring effectiveness in Information Security Controls

Measuring effectiveness in Information Security Controls (PDF, 1.98MB)Published: 06 Jul, 2010
Created by
Manuel Humberto Santander Peláez

The main purpose of the Information Security Analyst is to control the exposure to information security risks. However, the information security budget is not unlimited and there is increasingly a need to justify the return on investment for the controls implemented in our companies. How can we show the effectiveness of those controls? One way is to perform a risk analysis process to determine the controls to be implemented. The risk analysis process defines the critical variables that, when monitored, shows the risk exposure level and then determine the metrics that will measure the effectiveness of the controls. This paper shows a proposal on how to measure the effectiveness of implanted information security controls as part of the corporate Information Security process.