This bookdefines more than 900 metrics measuring compliance with current legislation, resiliency of security controls, and return on investment. It explains what needs to be measured, why and how to measure it, and how to tie security and privacy metrics to business goals and objectives. The metrics are scaled by information sensitivity, asset criticality, and risk; aligned to correspond with different lateral and hierarchical functions; designed with flexible measurement boundaries; and can be implemented individually or in combination. The text includes numerous examples and sample reports and stresses a complete assessment by evaluating physical, personnel, IT, and operational security controls.
Rezensionen / Stimmen
"Provides valuable directions on how measurement works and what goes into producing a useful metric. ... when faced with the necessity of developing a metrics program to measure the effectiveness of some aspect of your security efforts, this rather imposing tome is one I would recommend as a way to jumpstart your efforts. The master table in the introduction provides a quick guide to the particular section most relevant to the reader's need ..."
- Richard Austin, in IEEE Cipher, June 2007
"... a useful reference for individuals who must meet the challenge of selecting good metrics."
-Cheryl Washington, Information Security Officer, California State University, in Educause Quarterly
Sprache
Verlagsort
Verlagsgruppe
Zielgruppe
Für Beruf und Forschung
Corporate officers, security managers, internal and independent auditors, system developers and integrators, and systems and network management staff.
Illustrationen
28 s/w Abbildungen, 56 s/w Tabellen
28 b/w images, 56 tables and 100 equations
Dateigröße
ISBN-13
978-1-4200-1328-3 (9781420013283)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Klassifikation
Introduction, The Whats and Whys of Metrics, Measuring Compliance with Security and Privacy Regulations and Standards, Measuring Resilience of Physical, Personnel, IT, and Operational Security Controls, Measuring Return on Investment (ROI) in Physical, Personnel, IT, and Operational Security Controls