Lately I’ve been immersed in metrics for my day job at Tripwire. It’s been enlightening, to say the least. I thought that, for sure, we’d have a solid set of metrics to look at for this industry, but I think I’m wrong. Metrics are much harder than they may seem on the surface, and I’ve been learning a lot. Along the way, I’ve come across a model for security metrics published by ISO/IEC – ISO 27004 (Information technology – Security techniques – Information security management – measurement), published back in 2009.
-
Recent Posts
Recent Comments
- Adding To The Triad | Stoic Security & Compliance on Information Security Realities
- Announcing: Information Security Vocabulary Collaboration | Stoic Security & Compliance on Security Information Technology Dictionary Ontology
- Affecting Cybersecurity Behavior with Continuous Monitoring | Stoic Security & Compliance on Open and Transparent Information Assurance
- Making Security Automation a Reality | Stoic Security & Compliance on Security Automation Standards, Use Cases and Roles
- Adam on Complaints about Compliance Frameworks
Archives
Categories
Advertising