IT security metrics : a practical framework for measuring security & protecting data /

Hayden, Lance.

IT security metrics : a practical framework for measuring security & protecting data / Lance Hayden. - xxvii, 368 p. : ill.

Formerly CIP.

Includes bibliographical references and index.

Grounded in foundational concepts of risk management, decision support and basic economics, 'IT Security Metrics' provides a comprehensive approach to measuring risks, threats, operational activities and the effectiveness of data protection in your organization. Publisher's Note: Products purchased from Third Party sellers are not guaranteed by the publisher for quality, authenticity, or access to any online entitlements included with the product.Implement an Effective Security Metrics Project or ProgramIT Security Metrics provides a comprehensive approach to measuring risks, threats, operational activities, and the effectiveness of data protection in your organization. The book explains how to choose and design effective measurement strategies and addresses the data requirements of those strategies. The Security Process Management Framework is introduced and analytical strategies for security metrics data are discussed. You'll learn how to take a security metrics program and adapt it to a variety of organizational contexts to achieve continuous security improvement over time. Real-world examples of security measurement projects are included in this definitive guide.Define security metrics as a manageable amount of usable dataDesign effective security metricsUnderstand quantitative and qualitative data, data sources, and collection and normalization methodsImplement a programmable approach to security using the Security Process Management FrameworkAnalyze security metrics data using quantitative and qualitative methodsDesign a security measurement project for operational analysis of security metricsMeasure security operations, compliance, cost and value, and people, organizations, and cultureManage groups of security measurement projects using the Security Improvement ProgramApply organizational learning methods to security metrics




Electronic reproduction.
Askews and Holts.
Mode of access: World Wide Web.

9780071713412 (ebook)


Information technology--Security measures--Evaluation.
Data protection--Evaluation.
Computer security--Evaluation.
Computer crimes--Prevention--Measurement.
Computers and IT
Computer networking & communications
Network programming
Information technology: general issues
Internet browsers
Computer security
Privacy & data protection
Network security
Stationery items