SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Security group releases business-relevant metrics

Security group releases business-relevant metrics

By:  Kathleen Lau  On: 10 Sep 2008 For: ComputerWorld Canada Creator

The Center for Internet Security will make its metrics available as a community resource and will include ways of measuring vulnerability assessments and time to recover from security incidents. How you can use these metrics to improve your company’s security

According to Brian O’Higgins, chief technology officer with Ottawa-based intrusion prevention technology vendor Third Brigade Inc. , CIS’ metrics appear to have the right focus that ultimately impacts the business because often “security tools don’t always measure things that are the most important to the business units.”

To that point, O’Higgins cites a recent study by the Rotman School of Management and Telus that found IT professionals were the least satisfied with system log management tools among others. While the log management reports provide a plethora of data like system logs and alarms, he said the tools necessary to measure these recorded outcomes are still in their infant stages and don’t particularly demonstrate relevancy to the business.

“So, going all out,” said O’Higgins, “and measuring everything doesn’t mean you’re necessarily going to improve.”

While measuring outcomes is a necessary next step after amassing process data, O’Higgins acknowledged that, as with any tool on the market, there are opportunities for misdiagnosis that could lead IT managers to believe components of their infrastructure are more secure than they actually are.

But as relevant as metrics are at any given moment, they can’t remain static either, said O’Higgins, and must change with the morphing security threat landscape.










Sign up for our Newsletters












Print |  Views: 1158   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Related Content

Half of UK financial firms not ready for compliance
Half of UK financial firms not ready for complianceMore than half (51 per cent) of all U.K. firms have not implemented the security processes to comply with legislative directives such as PCI and MiFID, says a report.
Making a play for the infrastructure
Making a play for the infrastructureSymantec Corp. wants more presence in the enterprise IT infrastructure space and its spate of acquisitions and technology strategies are evidence of that move. ComputerWorld Canada senior writer Mari-Len De Guzman recently sat down with CEO and chairman John Thompson to explore that aspect of his company’s business and more
Is IT to blame for security woes?
Is IT to blame for security woes? IT professionals polled in a recent survey had an "unflattering" view of if their colleagues or managers. IT leaders don't much care about the end-user shenanigans, those polled claimed.
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof
blog comments powered by Disqus