Skip the navigation
Opinion

Measuring security

By Eddie Schwartz, netForensics Inc.
July 15, 2004 12:00 PM ET

Computerworld - Almost a year ago, I wrote a commentary in Computerworld asserting that true information security return on investment can't be proved and that quantitative risk-analysis models yield inaccurate or incomplete data.

Although I still believe that information security ROI is an elusive metric, further research has convinced me that CIOs can effectively measure the actual performance of information security investments and the linkages among performance, cost and opportunity.


Here are some thoughts on ways CIOs can use technology investments to gather and analyze the performance of information security technologies and controls, measure deviations from an accepted risk and cost baseline, and ensure that future investments provide measurable and quantifiable benefit to the enterprise.


Robert S. Kaplan and David P. Norton, in their article "Putting the Balanced Scorecard to Work," made a simple yet poignant statement: "What you measure is what you get." Information security organizations traditionally haven't been held to the same performance metrics as other areas of IT. For example, a network administrator is paid to provide service levels related to uptime, latency reduction and cost per gigabyte. A help desk manager is rated based on the number of "first-time-final" calls and factors such as queue hold time. What are we measuring for information security?


The distraction level to most areas of IT caused by security problems is very high. According to an Intel Corp. white paper, the company last year applied more than 2.4 million software patches. Bug fixes are being released on average every 5.5 days, and the time to react to vulnerabilities is getting shorter. According to the "Symantec Internet Security Threat Report" (Volume IV), 39% of vulnerabilities are exploited within zero to six months of discovery, and 64% within zero to 12 months of discovery.


Yet, according to Gartner Inc., computer networks without a comprehensive vulnerability management program are 5% to 7% patched. The bottom line here is cost. Given these statistics, if organizations can establish a risk baseline and find ways to monitor and manage that baseline to acceptable levels of deviation, there is opportunity for real cost savings.


Ways to measure security performance: Risk, time and cost


To build a meaningful performance management framework for information security, we must start with variables we can measure: threat level, vulnerability level, asset valuation, problem-resolution time and cost in terms of losses or savings.



For a system that's fully deployed and is in a production/operational state, let's assume that we've built the system as securely as possible and accepted residual risks that we couldn't resolve due to complexity or cost and that we now have a risk baseline of zero on Day 1. As time passes, events will cause this baseline to deviate from zero. For example, a new vulnerability will be discovered, and new patches and attacks (threats) will occur as a result. There may be unauthorized configuration changes or internal attempts to affect the confidentiality or integrity of the system. All of these factors together represent deviations from the risk baseline and can be quantified using the following equation:




Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs