¶ … Security Metrics
Governance of Information Security: Why Metrics Do Not Necessarily Improve Security
The objective of this study is to examine the concept that the use of various Metrics has tended to improve security however, Metrics alone may not necessarily improve security. This study will focus on two well-known metrics.
The work of Barabanov, Kowalski and Yngstrom (2011) states that the greatest driver for information security development in the majority of organizations "is the recently amplified regulatory environment, demanding greater transparency and accountability. However, organizations are also driven by internal factors, such as the needs to better justify and prioritize security investments, ensure good alignment between securities and the overall organizational mission, goals, and objectives, and fine-tune effectiveness and efficiency of the security programs." (p.1)
It is reported that a survey conducted by Frost and Sullivan demonstrated "that the degree of interest in security metrics among many companies (sample consisted of over 80) was high and increasing (Ayoub, 2006); while, in a global survey sponsored by ISACA, dependable metrics were perceived to be one of the critical elements of information security program success by many security professionals and executives, though, they were also deemed difficult to acquire (O'Bryan, 2006)." (Barabanov, Kowalski and Yngstrom, 2011, p.2)
In addition, it is reported that the focus on governance includes a "need for proper measurement and reporting on all the echelons within the organization, starting at the highest level. Another survey instigated by ISACA showed that organizations that are missing an information security governance project had identified metrics and reporting as the areas in their information security programs where the lack of quality was most noticeable." (Barabanov, Kowalski and Yngstrom, 2011, p.2) Barabanov, Kowalski and Yngstrom report that the correlation reported in their study highlights the requirement of recognizing "that measurement and reporting are connected with management on all organizational levels." (Barabanov, Kowalski and Yngstrom, 2011, p.2)
I. Defining Metrics
There is reported to be a great deal of ambiguity in relation to the precise definition of the term metric or 'security metric' according to Barabanov, Kowalski and Yngstrom (2011) since the terms "security metric and measure tend to be used interchangeably." (p.3) Definitions that have been proposed are stated to include those as follows:
(1) measure - A variable to which a value is assigned as the result of measurement where measurement is defined as the process of obtaining information about the effectiveness of Information Security Management Systems (ISMS) and controls using a measurement method, a measurement function, an analytical model, and decision criteria (ISO/IEC, 2009a).
(2) (IS) Measures - the results of data collection, analysis, and reporting, which are based on, and monitor the accomplishment of, IS goals and objectives by means of quantification (Chew et al., 2008).
(3) Metric - a consistent standard for measurement, the primary goal of which is to quantify data in order to facilitate insight (Jaquith, 2007)
(4) Metric - a proposed measure or unit of measure that is designed to facilitate decision making and improve performance and accountability through collection, analysis, and reporting of relevant data (Herrmann, 2007).
(5) Metrics - broad category of tools used by decision makers to evaluate data. A metric is a system of related measures that facilitates the quantification of some particular characteristic. In simpler terms, a metric is a measurement that is compared to a scale or benchmark to produce a meaningful result (McIntyre et al., 2007).
(6) Security Metrics - the standard measurement of computer security (Rosenblatt,2008).Although the specifics of the different definitions are subject to some variation, certain common characteristics generally emerge. (Barabanov, Kowalski and Yngstrom, 2011, p.20)
Primarily, metrics and measures are "considered to be measurement standards that that facilitate decision making by quantifying relevant data, where measurement refers to the process by which they are obtained. " (Barabanov, Kowalski and Yngstrom, 2011, p.20)
Stoddard, et al. (2005) reports that the term metrics "…describes a broad category of tools used by decision makers to evaluate data in many different areas of an organization. In its simplest form, a metric is a measurement that is compared to a scale or benchmark to produce a meaningful result." (p.3)
II. Characteristics of Good Metrics
The characteristics of good metrics is reported to include the following:
(1) Metrics should measure and communicate things that are relevant in the specific context for which they are intended, and be meaningful (in both the content and the presentation) to the expected target audience.
(2) The value of metrics should obviously not exceed their cost. Measures should be cheap/easy enough to obtain so that potential inefficiencies of data collection do not pull the resources needed for subsequent stages of measurement or in other parts and functions...
Metrics, Implementation, and Enforcement (Security Governance) How can you determine whether there has been a malware outbreak? The threat situation today has become more dangerous than in the past. Security and safety threats have been increasing in an alarming rate; there are more than 70,000 brand new bits of malware recognized daily. Well-funded cybercriminals have been currently making advanced malware that has been made to bypass present security options by launching prior
Health Information System Promoting Action Design Research to create value in healthcare through IT Recently there has been varying proof showing that health IT reduces costs while improving the standard of care offered. The same factors that had caused delays in reaping benefits from IT investment made in other sectors (i.e. time consuming procedural change) are also very common within the healthcare sector. Due to the current transitive nature of the Healthcare
Lufthansa Structure and Governance. Performance and Competition. Five-force analysis. Lufthansa is one of the oldest and most successful commercial airlines in the world, and is the fourth-largest in terms of passengers. However, the company has not always been so successful, and in fact was teetering on the brink of bankruptcy just a short while ago. By examining Lufthansa's history, structure, governance, and contemporary strategies and goals, one is able to see how the company
Based on the findings then, it is important for the Army National Guard to develop its infrastructure so that it responds to the KM needs. At the second level, the ARNG has to align its scopes and objectives with the knowledge management effort. At this stage, the risk resides in the inability to understand and apply knowledge management in the military setting. In order to overcome this, the company
The Price-Sensitive Affluents, Wal-Mart has learned (Wal-Mart Annual Reports) is more interested in finding an exceptionally good deal and not necessarily concerned about the shopping experience. This is particularly true as one of the strongest factors influencing the execution of their strategy, the emerging global recession during this timeframe, takes hold. Again as with the Price Value Shopper and the paradoxical purchasing patterns of the Brand Aspirational segment show,
Design criteria exist at the levels of the technical, system integration aspects of the database to other systems through XML. This integration is critically important to ensure that the applications created can be effectively used over time and not have any scalability issues. There is also the need for designing the databases at the presentation layer to provide for scalability and flexibility of being able to create applications relatively quickly
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now