Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Definitions: Security Metrics

0

Created on: Jan 27, 2009 10:15 AM by CrystalBedell - Last Modified:  Jan 27, 2009 10:19 AM by CrystalBedell

Definition

Security metrics are measurements of key performance indicators that help  organizations establish relationships between different dimensions of their  security strategy.

 

 

Business applications

Security metrics are often used to justify security spending to C-level executives, whether by illustrating the present risk or showing how  security investments have helped mitigate risk. For example, an organization  might measure the number of incidents that occurred within an IT infrastructure  during a given time period, and the amount of time and money needed to resolve  them. This data may help the organization demonstrate a need for additional  security spending or prove a return on technology investment.

 

 

Deployment Concerns

Given the dynamic nature of technology and the threat  landscape, security metrics quickly become outdated. They also lack standardization, so organizations  cannot easily compare their security posture to best practices or even other  organizations within the same industry. Organizations can deploy an automated  security metrics program to help ensure that metrics are current, but they are  still limited in their ability to compare metrics.

 

When presenting security metrics, IT professionals must be  careful to present the findings in relation to the business.  C-level executives and upper-management must be able to understand the business  impact of the security metrics to understand how they justify security  spending.

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

All About Reducing Your IT Costs

Looking to cut costs? Use this research-driven Excel tool to pinpoint which IT cost reduction measures best fit your needs.

Learn more >

Social Media Policies Toolkit

Define the rules at your company for the proper use of social media platforms such as Blogs, Twitter, Facebook and Youtube. Ensure your users are spending their time productively and company resources are being used for the business.

Learn more >

Comprehensive SMB Data Protection — Simplifying the D2D2T Paradigm

This white paper looks at the problems confronting IT managers in the SMB segment, describes a number of data protection technologies, and suggests data protection strategies that are particularly suited for small and medium business.

HP SiteScope Software Security Essentials

This white paper outlines how an agentless monitoring solution can securely transmit data and restrict access to satisfy even the most demanding security officer.