欢迎来到天天文库
浏览记录
ID:8006398
大小:2.84 MB
页数:48页
时间:2018-03-04
《information security metrics report外语英文电子书》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、PROTECTINGBUSINESSINFORMATIONfåÑçêã~íáçå=pÉÅìêáíó=jÉíêáÅëpéÉÅá~ä=fåíÉêÉëí=dêçìéj~ó=OMMSThisdocumentisconfidentialandpurelyfortheattentionofandusebyorganisationsthatareMembersoftheInformationSecurityForum(ISF).IfyouarenotaMemberoftheISForhaveWARNINGrec
2、eivedthisdocumentinerror,pleasedestroyitorcontacttheISFonisfinfo@securityforum.orgoron+44(0)2072131745.AnystorageoruseofthisdocumentbyorganisationswhicharenotMembersoftheISFisnotpermittedandstrictlyprohibited.Thisdocumenthasbeenproducedwithcareandtoth
3、ebestofourability.However,theInformationSecurityForumandInformationSecurityForumLimitedacceptsnoresponsibilityforanyproblemsorincidentsarisingfromitsuse.PROTECTINGBUSINESSINFORMATIONTableofcontentsPart1IntroductionThisreport1Purposeofthisreport1Whosho
4、uldreadthisreport1Basisforthisreport2Member-contributedmaterial2PreviousISFworkonsecuritymetrics3Part2AdefinitionofsecuritymetricsOverview4Whataresecuritymetrics?4Characteristicsofsecuritymetrics6Usageofsecuritymetrics7Part3Memberusageofsecuritymetric
5、sOverview8Amodelforunderstandingsecuritymetrics8Whysecuritymetricsareused9Whatsecuritymetricsareused10Howsecuritymetricsareused12Understandingtheissues14Part4Securitymetrics:mainissuesOverview15Whysecuritymetricsareused:issues16Whatiscurrentlyusedandc
6、ollected:issues17Howsecuritymetricsareused:issues18Addressingtheissues19Tableofcontents(continued)Part5Securitymetrics:keyactionsOverview20Keyactions20A:Definerequirements21B:Identifyrelevantsecuritymetrics23C:Collectdatarequired24D:Producesecuritymet
7、rics26E:Preparepresentations27F:Usedashboardsand/orscorecards29G:Reviewtheuseofsecuritymetrics31Relatingtheactionstothemodel31Part6ThewayforwardOverview32Tipsforimplementingsecuritymetrics32Possiblefuturework33Concludingremarks35AppendixASourcesofinfo
8、rmation36KeyFindings1Therearenoclearandcommondefinitionsofsecuritymetrics.However,theInformationSecurityForumbelievesthatsecuritymetricsshouldbeobjective,quantifiablemeasuresagainstspecifictargetsthatenableanorganisationtojudgetheeffectiveness
此文档下载收益归作者所有