SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis paper describes a method (almost a philosophy) for using the Critical Security Controls (CSCs) to drive long term improvement by carefully choosing specific metrics linked with operational processes. In contrast to formal process models, this method begins with identifying existing areas where (often small) changes can be used as starting points. Several examples are given using specific controls, concepts for driving change are presented, and the use of metrics as an underlying mechanism is discussed. The resulting organic approach promotes continuous improvement by taking advantage of natural behavioral tendencies of people and organizations.