05. Information Security Program Metrics Flashcards
Information Security Program Metrics
A measurement of a periodic or ongoing activity intended to help management understand the activity within the context of overall business operations.
A Metric
226
Information Security Program Metrics
Metrics are the means through which management can measure key processes and know…
whether their strategies are working
226
Information Security Program Metrics
Security metrics can be used to observe technical IT security controls and processes to determine if they are operating properly. Examples include…
- Firewall Metrics
- IDS/IPS Metrics
- Antimalware Metrics
- Others…
- Number and types of rules triggered
- Number and types of incidents detected or blocked
- Number and types of malware blocked
- DLP systems, web content filtering, CASB etc..
226
Information Security Program Metrics
Board of directors and executive management are interested non technical metrics and instead metrics that demonstrate..
the effectiveness or alignment of the organisations overall security program
226
Information Security Program Metrics
Metrics associated with risk measurement
Key Risk Indicators
(KRI)
226
Information Security Program Metrics
Metrics that portray the attainment of strategic goals
Key Goal Indicators
(KGI)
226
Information Security Program Metrics
Metrics that show the efficiency or effectiveness of security related activities
Key Performance Indicators
(KPI)
226
Monitoring
The continuous or regular evaluation of a system or control to determine its operation or effectiveness
Monitoring
227
Monitoring
Monitoring generally includes 2 activities…
- Management review of certain qualitative aspects of an information security program
- Management review of key metrics to understand effectiveness, efficieny, performance
227
Effective Metrics
For metrics to be effective, the need to be measurable. A SMART metric is…
- Specific
- Measurable
- Attainable
- Relevant
- Timely
227
Effective Metrics
3 considerations for good metrics is…
- Leading indicator
- Causal Relationship
- Influence
- Predict future risk?
- Causal relationship to business impact - a change in a metric causes someone to act
- Can the metric or has it, influence(d) decision making
227
Strategic Alignment
A security program strategy adn objectives should contain statements that…
can be translated into key measurements
Statements that can be the programs key performance and risk metrics
227
Types of metrics
Multiple activities and events in an information security program and its controls can be measured. 11 key examples include….
- Compliance
- Convergence
- Value Delivery
- Resource Management
- Organisational Awareness
- Operational Productivity
- Organisational Support
- Risk Management
- Technical Security Architecture
- Opertional Performance
- Security Cost Efficiency
228-231
Types of metrics
A metric used to measure key controls related to requirements in regulations, legal contracts, or internal objectives
Compliance Metric
228
Types of metrics
A metric that is highly individualised, based on specific circumstnaces in an organisation and may include one or more of the following;
- Gaps in asset coverage
- Overlaps in asset coverage
- Consolidation of licences for security tools
- Gaps or overlaps in skills, responsibilities, or coverage
Convergence Metric
228