資源描述:
《information security metrics report外語英文電子書》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在教育資源-天天文庫。
1、PROTECTINGBUSINESSINFORMATIONf???ê?~íá??=pé?ìêáíó=jéíêá??péé?á~?=f?íéêé?í=dê?ìéj~ó=OMMSThisdocumentisconfidentialandpurelyfortheattentionofandusebyorganisationsthatareMembersoftheInformationSecurityForum(ISF).IfyouarenotaMemberoftheISForhaveWARNINGrec
2、eivedthisdocumentinerror,pleasedestroyitorcontacttheISFonisfinfo@securityforum.orgoron+44(0)2072131745.AnystorageoruseofthisdocumentbyorganisationswhicharenotMembersoftheISFisnotpermittedandstrictlyprohibited.Thisdocumenthasbeenproducedwithcareandtoth
3、ebestofourability.However,theInformationSecurityForumandInformationSecurityForumLimitedacceptsnoresponsibilityforanyproblemsorincidentsarisingfromitsuse.PROTECTINGBUSINESSINFORMATIONTableofcontentsPart1IntroductionThisreport1Purposeofthisreport1Whosho
4、uldreadthisreport1Basisforthisreport2Member-contributedmaterial2PreviousISFworkonsecuritymetrics3Part2AdefinitionofsecuritymetricsOverview4Whataresecuritymetrics?4Characteristicsofsecuritymetrics6Usageofsecuritymetrics7Part3Memberusageofsecuritymetric
5、sOverview8Amodelforunderstandingsecuritymetrics8Whysecuritymetricsareused9Whatsecuritymetricsareused10Howsecuritymetricsareused12Understandingtheissues14Part4Securitymetrics:mainissuesOverview15Whysecuritymetricsareused:issues16Whatiscurrentlyusedandc
6、ollected:issues17Howsecuritymetricsareused:issues18Addressingtheissues19Tableofcontents(continued)Part5Securitymetrics:keyactionsOverview20Keyactions20A:Definerequirements21B:Identifyrelevantsecuritymetrics23C:Collectdatarequired24D:Producesecuritymet
7、rics26E:Preparepresentations27F:Usedashboardsand/orscorecards29G:Reviewtheuseofsecuritymetrics31Relatingtheactionstothemodel31Part6ThewayforwardOverview32Tipsforimplementingsecuritymetrics32Possiblefuturework33Concludingremarks35AppendixASourcesofinfo
8、rmation36KeyFindings1Therearenoclearandcommondefinitionsofsecuritymetrics.However,theInformationSecurityForumbelievesthatsecuritymetricsshouldbeobjective,quantifiablemeasuresagainstspecifictargetsthatenableanorganisationtojudgetheeffectiveness