Analytics

10/23/2015
09:30 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Passing the Sniff Test: Security Metrics and Measures

Cigital dishes dirt on top security metrics that don't work well, why they're ineffective and which measurable to consider instead.
Previous
1 of 9
Next

Image: Adobe Stock

Image: Adobe Stock

 

Security metrics are one of the key pillars of establishing a mature cybersecurity program. We’ve spilled a lot of digital ink over the years at Dark Reading discussing some of the top security metrics that organizations should consider collecting and analyzing. But are all security metrics good ones? According to Caroline Wong, security initiative director at Cigital, the short answer is, ‘Nope!’ She’s seen organizations waste resources on measuring things that don’t really matter to the business and do nothing to help drive improvement.

“I've really been doing security metrics for about ten years, so I've had more time to think about stuff,” she says. “And one of the things that I've realized is that there are some metrics which organizations track that I really just don't think are useful.”

Caroline gave us the lowdown on metrics effectiveness. She started by offering some key sniff tests for determining if your metric is a stinker. Then she offered up some examples of ineffective metrics, as well as alternatives that will better help move the needle for security.   

 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
10/26/2015 | 8:01:43 AM
Displaying Value
Whenever you are trying to devise important metrics of either a tool you own or a process think of the metric by the value it provides. Does it delineate cost savings, does it help to point out a broken business process, etc.
copleydt
50%
50%
copleydt,
User Rank: Apprentice
10/24/2015 | 10:39:51 AM
Practical Advise
Your article was right on the spot; very pragmatic and useful. I've been in security a long time and am currently a CISO for a large healthcare provider and I've seen some metrics which I consider to be of no value.  I speak on security fairly often and I was just contemplating assembling a presentation on this same topic -  what security metrics NOT to use and what you SHOULD be measuring.
Devastating Cyberattack on Email Provider Destroys 18 Years of Data
Jai Vijayan, Freelance writer,  2/12/2019
Up to 100,000 Reported Affected in Landmark White Data Breach
Kelly Sheridan, Staff Editor, Dark Reading,  2/12/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8358
PUBLISHED: 2019-02-16
In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.
CVE-2019-8354
PUBLISHED: 2019-02-15
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.
CVE-2019-8355
PUBLISHED: 2019-02-15
An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsx_valloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow in channels_start in remix.c.
CVE-2019-8356
PUBLISHED: 2019-02-15
An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow.
CVE-2019-8357
PUBLISHED: 2019-02-15
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference.