Master the techniques, practices, theories, and business applications of computer network security metrics
* Learn the process and techniques for aggregating data and developing metrics
* Master analytical tools and a framework for quantifying the state of an organization's security
* Review examples that show the effectiveness of metrics, and learn how to communicate them to senior management
Table of Contents
Foreword
xv
Preface
xix
Acknowledgments
xxv
About the Author
xxviii
Chapter 1
Introduction: Escaping the Hamster Wheel of Pain
1
Chapter 2
Defining Security Metrics
9
Chapter 3
Diagnosing Problems and Measuring Technical Security
39
Chapter 4
Measuring Program Effectiveness
89
Chapter 5
Analysis Techniques
133
Chapter 6
Visualization
157
Chapter 7
Automating Metrics Calculations
217
Chapter 8
Designing Security Scorecards
251
Index
301
About the Authors
Andrew Jaquith is the program manager for Yankee Group's Enabling Technologies Enterprise group, with expertise in compliance, security, and risk management. Jaquith advises enterprise clients on how to manage security resources in their environments. He also helps security vendors develop strategies for reaching enterprise customers. Jaquith's research focuses on topics such as security management, risk management, and packaged and custom web-based applications.
Jaquith has 15 years of IT experience. Before joining Yankee Group, he cofounded and served as program director at @stake, Inc., a security consulting pioneer, which Symantec Corporation acquired in 2004. Before @stake, Jaquith held project manager and business analyst positions at Cambridge Technology Partners and FedEx Corporation.
His application security and metrics research has been featured in CIO, CSO, InformationWeek, IEEE Security and Privacy, and The Economist. In addition, Jaquith contributes to several security-related open-source projects.
Jaquith holds a B.A. degree in economics and political science from Yale University.