Skip the navigation

Security Manager's Journal: A metrics system for the CIO

Quarterly reports to the CIO will keep him aware of risks in the environment, and hopefully will reduce those risks.

By Mathias Thurman
March 21, 2011 06:00 AM ET

Computerworld - Metrics can have a very interesting effect. You just have to present them properly.

Trouble Ticket

At issue: You don't know where some dangers lurk unless you look for them.

Action plan: Develop a regular program of metrics, and find an interesting way to present them to the CIO.

I spent the past week deciding which metrics I want to collect and present to the CIO on a quarterly basis, and how I will present them. I'm using Microsoft SharePoint to collect my metrics and will export the results to an Excel spreadsheet so that I can create some interesting pivot tables and charts. The idea is that I simply have to input the data, and the resulting presentation will be automated. I can even incorporate the Excel charts into PowerPoint so that I only have to open the presentation each quarter and the data will be updated automatically. And, if I can pull it off, I can have some of the metrics automatically populate my SharePoint list. Gotta love automation!

To begin with, I'm conducting discovery scans on the entire enterprise to identify the total number of devices (beginning with PCs and servers) connected to the network. I'm using Nessus to conduct these scans, since it's a fairly robust independent tool. The price is reasonable for a one-year license, and it lets us scan our entire address range. I'm also using Altiris, which is a Symantec tool that we use for software distribution and reporting. And finally, there's Symantec AntiVirus Server for reporting on antivirus compliance.

Initial results are alarming. Our company has about 3,000 workers (including contractors). You would think that a discovery scan of desktops would yield about 3,000 unique desktop-class PCs, with workers who are not in the office offset by those who have more than one PC. Our result: 4,200 PCs! Next, I generated a report to see how many of those PCs have the Altiris Agent installed so that we can control the configuration. Only 2,400. This means there are 1,800 PCs whose integrity we can't vouch for. And any unmanaged resource represents risk.

I did the same for servers. I obtained all the IP address spaces for each data center and remote office and conducted discovery scans of all resources that looked like they were running a server operating system. The result: 1,200 servers (including virtual machines). Next, Altiris reported only 800 servers, leaving 400 that we know nothing about. And 30 of those servers are in our DMZ!

Besides reporting the ratio of managed to unmanaged devices, I will be reporting on how many of those devices are in compliance with our patch management policy. We apply Microsoft patches one month after they are released, giving us time to test different environments and applications. I'll also report on the number of resources that are in compliance with our antivirus/spyware policy, meaning they have the most updated software and pattern file.

And finally, I'll report on security events. Why? Because I need to show the direct correlation between security events and lack of compliance in order to drive change. I guarantee that unless you have other compensating controls in place, such as IPS or other activity-blocking infrastructure, incidents rise when resources aren't patched or in compliance with antivirus policy.

My plan is to report to the CIO every quarter on the number of managed and unmanaged devices, and the data related to patches, antivirus and incidents. This will make him aware of the status of the environment (after all, the CIO is ultimately responsible for IT) and hopefully drive change in our risk exposure. Will I be the most popular guy in the room? Probably not. Are these metrics relevant? Absolutely. And until we implement network access control to interrogate each and every device that is attached to our network, we will continue to have issues in this area.

This week's journal is written by a real security manager, "Mathias Thurman," whose name and employer have been disguised for obvious reasons. Contact him at mathias_thurman@yahoo.com.

Join in the discussions about security! computerworld.com/blogs/security

Read more about Security in Computerworld's Security Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs