Access "Security: Measuring Up"
This article is part of the February 2005 issue of 12 security lessons for CISOs they don't teach you in security school
Here's a formula most security pros will recognize: Risk = Threat x Vulnerability x Expected Loss It's useful for expressing the necessity and purpose of security. It's also equally difficult to quantify with meaningful numbers. How do you numerically express a threat? What is the cost of a vulnerability? How do you calculate expected loss? And, when you multiply these three variables, how do you denote risk in a way that can be translated into an action item? Security metrics--the measure of security policies, processes and products--is the much-sought-after solution to this conundrum. Security managers look for a magic formula that calculates risk and effectiveness in reducing risk, but the reality is that security metrics aren't that simple. Measuring security is about using common sense. Managers need to determine what to measure, organize the variables in a way that makes them manageable and meaningful, and build repeatable formulas that show the snapshot status of security and how it changes over time. We'll define some of the underlying elements ... Access >>>
Premium Content for Free.
Secure Reads: The Network Security Bible
A review of the Network Security Bible by Eric Cole, Ronald Krutz and James W. Conley
Desktop Security: Senforce Portable Firewall Plus
Senforce's Senforce Portable Firewall Plus
Wireless security product review: AirTight Networks' SpectraGuard 2.0
A review of AirTight Networks' SpectraGuard 2.0
Database Security: Ingrian i211 DataSecure Platform
Ingrian Networks' Ingrian i211 DataSecure Platform
In MSSPs We Trust
Regulatory and cost-cutting pressures are forcing enterprises to reexamine the value of managed security services.
On the Job
12 lessons they don't teach you in security school about being a CISO.
- Secure Reads: The Network Security Bible
Recent Releases: Security product briefs, February 2005
Learn about the security products launched in February 2005.
IronPort C-Series Messaging Gateway: Antivirus, Antispam tool
Enhance your email security strategy with IronPort's C-Series Messaging Gateway. In this product review you will get information on cost, installation, reporting, configuration, and antivirus and antispam technology.
Hot Pick: Funk Software's Odyssey Client 3.03 and Odyssey Server 2.01
by Steven Weil, Contributor
Funk Software's Odyssey Client 3.03 and Odyssey Server 2.01
SSHv2: Safe & Secure
The overhauled encryption protocol helps harden networks.
Security: Measuring Up
by Pete Lindstrom, Contributor
Metrics are the key to measuring security. Learn how to gather data and calculate the answers you need.
- Recent Releases: Security product briefs, February 2005
Logoff: The battle against spyware
On the Radar
Perspectives: Symantec, Veritas pairing to change security
Symantec's merger with Veritas will change security managers' lives.
Editor's Desk: Nessus charges for signature updates
No Free Lunches
- Logoff: The battle against spyware
More Premium Content Accessible For Free
Despite the enormous concerns around cloud security, many information security professionals remain on the sidelines when it comes to their ...
Not only is modern malware getting more prevalent and sophisticated, it's also now focusing on a broader array of targets. Attackers would still love...
IT Decision Center
Learn how to evaluate your potential vendor's UTM product and its ability to meet your specific business requirements.