Passing the Sniff Test: Security Metrics and Measures

Cigital dishes dirt on top security metrics that don’t work well, why they’re ineffective and which measurable to consider instead.

 

Security metrics are one of the key pillars of establishing a mature cybersecurity program. We’ve spilled a lot of digital ink over the years at Dark Reading discussing some of the top security metrics that organizations should consider collecting and analyzing. But are all security metrics good ones? According to Caroline Wong, security initiative director at Cigital, the short answer is, ‘Nope!’ She’s seen organizations waste resources on measuring things that don’t really matter to the business and do nothing to help drive improvement.

“I've really been doing security metrics for about ten years, so I've had more time to think about stuff,” she says. “And one of the things that I've realized is that there are some metrics which organizations track that I really just don't think are useful.”

Caroline gave us the lowdown on metrics effectiveness. She started by offering some key sniff tests for determining if your metric is a stinker. Then she offered up some examples of ineffective metrics, as well as alternatives that will better help move the needle for security.   

 

About the Author

Ericka Chickowski, Contributing Writer

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights