Forrester advise easy to understand security metrics

Forget about keeping out of the headlines, deliver figures the budget holders understand

Organisations overcomplicate the way they measure security and would benefit from a much simpler approach, according to analyst group Forrester.

Speaking ahead of the Forrester Security Forum held in London today and tomorrow, Andrew Jacquith, senior analyst at the firm, acknowledged it was difficult to measure the effectiveness of security. “It tends to be very emotional, we make decisions based on perceptions of risk and headlines in newspapers. This isn’t a good way to judge.”

To measure the strength of your security easily and accurately, organisations should define their security measures into clear areas, and develop simple and consistent metrics, he told CIO UK sister title Computerworld UK.

Jacquith advised businesses to produce a simple number for each measurement that puts the quality of security into context, for example, "what percentage of laptops are covered by anti-malware programmes, how many network intrusions have taken place divided by the number of users on the network, or what percentage of intrusions were detected by systems rather than found later accidentally".

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Creating simple numbers that demonstrated the strength of security was far more effective than complex metrics, which can be difficult to decode and mean little in a business context, he said.

“Executives don’t have a lot of time, and they want simple answers they can rely on. The security industry has not been good at a developing a non-technical explanation.”

The act of measuring progress, and the discipline required, improves security and demonstrates to managers its value, he said. “With budgets the way they are, we know how important that is.”

For all the latest security ideas, news and thought leadership visit the CIO UK Security Tech Toolkit



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

5 steps to successful IT consolidation and virtualisation

There are many benefits associated with IT consolidation and virtualisation, but it can be a very challenging process. It is important to consider all components of an IT consolidation project before embarking on it.

Anatomy of insider risk

Learn the four steps to minimizing the risk from negligent insiders.

The foundation for wireless without compromise

In this white paper, we have discussed the three phases of WLAN architecture evolution i.e. WLAN for convenience (limited adoption), WLAN as the network of choice (instead of wires) and WLAN for business critical applications. We have also compared legacy microcell architectures to Meru’s Air Traffic Control™ architecture and provided guidance on selection of the right architecture.

Mobile and flexible working for efficiency and effectiveness

The technology of mobile and flexible working has much to offer, providing all that is needed for remote access, effective data sharing and the ability to work in a time efficient way from a variety of ‘desktop productivity’ endpoint devices.


CIO UK - Business - Technology - Leadership

Media Usage Survey - Win an iPad

How do you view and share technology related content and information. Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Enterprise Cloud Computing

Every week, we present new questions and issues for discussion and debate. Follow us and join in!

Join the community

Enterprise Intelligence

Exploring challenges, solutions and requirements for business intelligence and financial management. A new resource centre hosted on CIO UK, sponsored by SAP.

Visit

SAP



* *