Transcription of Information Security Effectiveness Metrics: What Metrics ...
{{id}} {{{paragraph}}}
IBM Global ServicesSecurity & Privacy ServicesInformation Security EffectivenessInformation Security EffectivenessMetrics: what Metrics ? what Role for Metrics ? Metrics : what Metrics ? what Role for Metrics ?MatundaNyanchama, PhD, CISSPN ational Leader, Security & Privacy Delivery ServicesIBM Global Services, CanadaE-mail: & PrivacyIBM Global ServicesNovember 21, 2004 November 21, 200422 Copyright IBM Global ServicesCopyright IBM Global ServicesAgendaAgenda Background Some Definitions Why Metrics ? IS Metrics -Background Value Information Security Metrics Metrics Development Process Scope of Measurement ISO 17799 Scoping out IS Metrics Information Security Program Example Scope of Considerations for Measurement Examples of Measures Metrics & Reporting Data Sources for IS Metrics IS Metrics Process & Reporting Metrics Breadth, Depth & Purpose Incident Management Example Sample IS Dashboard State of IS Metrics & Caveats & Some Suggestions SummarySecurity & PrivacyIBM Global ServicesNovember 21, 2004 November 21, 200433 Copyright IBM Global ServicesCopyright IBM Global ServicesSome DefinitionsSome Definitions Metric: relating to measurement; involving, or proceeding by, measurement (Webster s Revised Unabridged Dictionary) Information Security pertains to integrity, confidentiality& availability;auditabilityandaccountabili ty Security Metric: A measurable attribute of the result of a Security engineering process that could [be] evidence its Effectiveness .
The IS Management Life Cycle. Maintain & Improve Security Management Program Monitor & Continuously Review Program Performance Establish Information
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}
The Insider Threat to Information Systems, Information Systems Security, Information systems, Information Security, Information Security Systems, Skillsoft, Security Information, Security, Information, Systems, Information Security – Awareness and Training Procedures, Research Paper: Information Security Technologies, For Information Security PREVIEW VERSION, ISACA, The information, Risk Assessment of Information Technology Systems, Networking and Information Security