For Security & Risk Professionals (Length: 16 pages)

July 22, 2008

Best Practices: Security Metrics

by Khalid Kark

with Jonathan Penn, Alissa Dill, Allison Herald, Margaret Ryan


Executive Summary (This is a document excerpt)

Security metrics are a key initiative for many chief information security officers (CISOs) today, but many of them struggle with picking the right security metrics and translating the operational measurements into meaningful metrics for business. Forrester interviewed more than 20 companies in various stages of their security metrics programs, and some that have successfully implemented them, to glean best practices and lessons learned from those efforts. The three main themes that came out of this research are: Be very selective in picking your security metrics, think beyond the security organization, and focus on reporting and presentation.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemCISOs Struggle To Find The Right Metrics

itemBest Demonstrated Practices In Security Metrics

itemSecurity Metrics Best Practice No. 1: Be Very Selective In Picking The Metrics

itemSecurity Metrics Best Practice No. 2: Think Beyond The Security Organization

itemSecurity Metrics Best Practice No. 3: Focus On Reporting And Presentation

itemForrester's Security Metrics Next Practices

itemIdentifying Your Challenges

itemCase Studies

itemSupplemental Material

Forrester interviewed more than 20 different companies.

Related Research Documents

itemCase Study: Verizon Business Builds An Asset-Based Security Metrics Program

July 22, 2008

itemAre We Secure Yet?

March 31, 2006

itemThe Myths Of Information Security Reporting

March 23, 2006

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Khalid Kark
Technology: Security & Risk, Security Operations, Security Program Governance
Geography: Asia Pacific, Europe, North America

Archived Teleconference:
The Managed Security Services Market Landscape
Original air date: Friday, October 30, 2009
corner border corner
Ratings and Comments
Rating: 8 out of 10
based on 4 ratings across all roles.
corner border corner