Other books on information security metrics discuss number theory and statistics in academic terms. Light on mathematics and heavy on utility, PRAGMATIC Security Metrics: Applying Metametrics to Information Security breaks the mold. This is the ultimate how-to-do-it guide for security metrics.
Packed with time-saving tips, the book offers easy-to-follow guidance for those struggling with security metrics. Step by step, it clearly explains how to specify, develop, use, and maintain an information security measurement system(a comprehensive suite of metrics) to help:
- Security professionals systematically improve information security, demonstrate the value they are adding, and gain management support for the things that need to be done
- Management address previously unsolvable problems rationally, making critical decisions such as resource allocation and prioritization of security relative to other business activities
- Stakeholders, both within and outside the organization, be assured that information security is being competently managed
The PRAGMATIC approach lets you hone in on your problem areas and identify the few metrics that will generate real business value. The book:
- Helps you figure out exactly whatneeds to be measured, howto measure it, and most importantly, whyit needs to be measured
- Scores and ranks more than 150 candidate security metrics to demonstrate the value of the PRAGMATIC method
- Highlights security metrics that are widely used and recommended, yet turn out to be rather poor in practice
- Describes innovative and flexible measurement approaches such as capability maturity metrics with continuous scales
- Explains how to minimize both measurement and security risks using complementary metrics for greater assurance lÃÊ