Welcome Guest. | Log In | Register | Membership Benefits

Five Strategic Security Metrics To Watch

Is your security program paying off for the business? Here are five high-level metrics that the executive suite needs to watch

Feb 24, 2012 | 05:32 PM | 

By Robert Lemos, Contributing Writer
Dark Reading


Information security specialists like to argue over a lengthy list of possible metrics to measure their systems' security posture.

For managers and executives, however, the picture needs to be simplified to a less controversial collection of measurements. While security administrators focus on technical metrics, managers and chief security officers have to focus on how IT security interacts with business, says Kevin Lawrence, senior security associate with IT security consultancy Stach & Liu.

"Everything comes down to whether the business impact is worth the security reward," says Lawrence. "It does not makes sense to close a vulnerability if you can't then do business."

Earlier this month, industry experts weighed in on their top-5 metrics for tactical security, such as identifying dark parts of their own network and the total attack surface area. In interviews, analysts and security professionals offered a higher-level, more strategic mix of metrics to measure as well.

While some of these metrics may not directly correlate to security, getting high marks means that a company has a good level of control over its systems, network and data -- and that means security, says Andrew Jaquith, chief technology officer of security services firm Perimeter e-Security.

"Running a tighter shop, with more control, is always good for security," he says. "It means that you can react very quickly if you have to change something."

Here are five security metrics to track for businesses.

1. Keep up with the Joneses
A starting point for many companies is whether they are spending as much as the median firm in their industry. In 2012, security is expected to account for 7 percent of information-technology budgets as a whole, according to business intelligence firm Forrester Research. The number varies by industry with financial services tending to spend more, and healthcare and manufacturers spending less.

"If your industry partners are spending six percent of their IT budget on security and you are spending two percent, that's probably an issue," says Stach & Liu's Lawrence.

While the metric does not indicate how well companies are spending their security dollars, it is a good high-level measurement.

2. High-performance patching
Keeping track of how long it takes to apply a patch to all corporate systems is another critical metric, says Perimeter's Jaquith. Measuring patching latency puts the premium on speed and that's what important. A week or less is best, he says.

"Patching is not everything -- there is a lot of zero-days out there," Jaquith says. "But there is an exceptionally high correlation between exploits in the wild and vulnerabilities that could be patched."

While patching is not necessarily equivalent to security, it's an indicator of whether a company has good control over its systems. A company that patches quickly is likely far more aware of vulnerabilities and the state of its systems' security, he says.

"It's not so much whether patching solves your problem, but it is a key performance indicator of whether or not you are running a tight shop," Jaquith says.

3. All the same, more secure
For many companies, keeping systems up-to-date with a standard image allows their workers to more efficiently maintain and secure the dozens, or hundreds, of software programs on each system. Standardization can also help companies ensure that all their systems comply with any regulations that affect the business.

For that reason, tracking the proportion of standardized systems can give an indication of the effort required to secure information assets, says Stach & Liu's Lawrence.

"If you have 100 different computers in your environment and only 80 are standard, then you have a pretty big gap there that you need to close," he says.

4. Checking off the boxes quickly
Companies have to comply with an increasing number of regulations or mandates from their clients and customers. Measuring how quickly the business's workers check off the most critical boxes is a good measure of security operations as well, says Perimeter's Jaquith.

"This is good from a project planning standpoint, which helps you understand how well you can handle your security initiatives," he says.

Because most IT security teams are overwhelmed with lists of to-do items, the best metric is to only focus on only the most critical issued found during an audit -- "the ones marked in red," Jaquith says.

5. Tame the Cowboy Infrastructure
Finally, companies that have frequent emergency patching and maintenance issues -- not to mention downtime -- are generally less secure, says Jaquith. Emergency changes are typically an indicator that the infrastructure is not well managed, he says.

"If 50 percent of your changes are done as emergency changes and not in your typical maintenance windows, you have a cowboy infrastructure," he says. "And cowboys do not lead to good operations, and more importantly, they don't lead to secure outcomes."

Most organizations have scheduled downtime or maintenance windows for backing up, patching and other activities. Keeping any activity that could impact security in those windows indicates that security and IT teams are planning adequately.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Security Monitoring Reports

report Fundamentals of User Activity Monitoring
Benchmarking normal activity and then monitoring for users who stray from that norm is an essential strategy for getting ahead of potential data and system breaches. But choosing the right tools is only part of the effort. Without sufficient training, efficient deployment and a good response plan, attackers could gain the upper hand.

report Does SIEM Make Sense For Your Company?
A security information and event management system serves as a repository for all the security alerts and logging systems from a firm's devices. But this can be overkill for a company that is understaffed or has overestimated its security information needs. In this report, we discuss 10 questions to ask yourself in determining whether SIEM makes sense for you--and how to pick the right system if it does.

report Monitoring Tools and Logs Make All The Difference
It's no longer a matter of "if" you get hacked, but when. In this special report, we take a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape.

Other reports from the Security Monitoring Tech Center:

Related Content

Security Management 2.0: Time to Replace Your SIEM?
Is it time? Are you waving the white flag? Has your first gen SIEM failed to meet expectations despite your investment? If you are questioning whether your existing product or service can get the job done, you are not alone. Read this Securosis white paper to learn how easy it can be to replace your SIEM with a next generation solution.

IT Executive Guide to Security Intelligence: Transitioning from SIEM to Total Security Intelligence
Read this whitepaper to learn how adopting a next generation SIEM solution provides security intelligence, to allow organizations to maintain comprehensive and cost-effective information security. Discover how security intelligence enables critical concerns in five key areas: Data silo consolidation, threat detection, fraud discovery, risk assessment/risk management, and regulatory compliance.

The Return on Security of QRadar: Improving Operational Efficiencies in Federal Government
In this study, IANS interviewed two Q1 Labs customers using QRadar to assess their Return On Security (ROS). The two customers were providers of service to the U.S. Government and had highly secure environments dealing with extremely sensitive data. The data yielded from the interviews showed substantial benefit to the organizations for the cost, both in money and staff time.

SANS What Works Webcast: Worldwide Retailer Boosts Privacy with Security Intelligence
A leading retailer with stores worldwide was seeking a more innovative tool to protect customer privacy and intellectual property. PCI compliance mandated log collection, but a vast number of different tools generated an overwhelming amount of log data, making it difficult for the small security team to review it effectively. The solution the company chose had to fit into a diverse network, provide intelligent reporting and offer a centralized management console.

Learn How Security Intelligence Can Help Combat WikiLeaks Stuxnet and Advanced Threats
WikiLeaks and Stuxnet have illustrated a few fundamental IT security issues that have underscored the need for Total Security Intelligence to counter advanced threats and to detect anomalous behavior. See how government and commercial organizations are using QRadar as an integral component of their IT security program to identify emerging threats based on context and situational awareness.




Featured Webcasts
Featured Whitepapers
Featured Reports