Praise for IT Security Metrics

“I think that one reason security metrics is so hard is because there is no single recipe for success. It is not just about the math. It is about understanding what knowledge you seek and how quantitative analysis can help. To create a successful and sustainable metrics program, you must start with a well-reasoned framework. Lance’s book begins by presenting one. He then enriches the theory with practical case studies that illustrate how you can incorporate the framework into your own context. This treatment has something new to say to security measurement veterans and beginners alike.”

—Elizabeth A. Nichols, Ph.D., PlexLogic, LLC

“The author provides a timely and practical overview of information security management that speaks directly to people charged with performing the tasks. It takes you from overview to application in clear, readable chapters that emphasize real-world application over technical details. This book will give you the insights and confidence to apply the metrics that matter for your organization.”

—Andrew Dillon, Dean and Yule Regents
Professor of Information Science,
School of Information, University of Texas

“Security practitioners everywhere are making a concerted effort to measure what we do so that we can be more productive, more efficient, and can demonstrate the security we deliver. This book is rich in real-world experiences and offers the kinds of practical approaches we all need to apply to security metrics.”

—Dr. Mike Lloyd, Chief Scientist,
RedSeal Systems, Inc.

“Today’s security practice is about efficacy and that requires a sound measurement process and metrics reporting. This is no longer about cobbling together best practices, following groupthink, or continuing a practice simply because we have always done it that way. Effective security practice is about setting a strategy, implementing it, and proving it works. IT Security Metrics by Lance Hayden codifies the differences between measurement and metrics, reminds us all that you get what you measure so be mindful before starting, and seeks not only to demystify but to augment our industry’s current practice, which too often is to add more to—instead of getting more from—what you already have.”

—John N. Stewart, Cisco Vice President
and Chief Security Officer

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.222.93.132