Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Definitions: Security Metrics

0

Created on: Jan 27, 2009 10:15 AM by CrystalBedell - Last Modified:  Jan 27, 2009 10:19 AM by CrystalBedell

Definition

Security metrics are measurements of key performance indicators that help  organizations establish relationships between different dimensions of their  security strategy.

 

 

Business applications

Security metrics are often used to justify security spending to C-level executives, whether by illustrating the present risk or showing how  security investments have helped mitigate risk. For example, an organization  might measure the number of incidents that occurred within an IT infrastructure  during a given time period, and the amount of time and money needed to resolve  them. This data may help the organization demonstrate a need for additional  security spending or prove a return on technology investment.

 

 

Deployment Concerns

Given the dynamic nature of technology and the threat  landscape, security metrics quickly become outdated. They also lack standardization, so organizations  cannot easily compare their security posture to best practices or even other  organizations within the same industry. Organizations can deploy an automated  security metrics program to help ensure that metrics are current, but they are  still limited in their ability to compare metrics.

 

When presenting security metrics, IT professionals must be  careful to present the findings in relation to the business.  C-level executives and upper-management must be able to understand the business  impact of the security metrics to understand how they justify security  spending.

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

All About Reducing Your IT Costs

Looking to cut costs? Use this research-driven Excel tool to pinpoint which IT cost reduction measures best fit your needs.

Learn more >

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >

Tablet PCs

Powerful and portable computing capacity for today's high-speed, fluid business environment.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

Information Management

Tools, tips and solutions to help you manage your data more efficiently to tackle today's challenging economic environment.

Data Loss Protection

Data-loss prevention tactics, technologies and best practices to protect your sensitive and valuable company data.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Performance Under Pressure: The State of Enterprise Web Application Quality and Availability

This research study finds that Web application issues are an all-too-common problem and examines these Web-based enterprise application issues from two perspectives: that of an online customer and that of a site manager.