A Few Good Metrics
This is a very good article covering the basics of the difficult topic of Information Security Metrics.
“Information security metrics don’t have to rely on heavy-duty math to be effective, but they also don’t have to be dumbed down to red, yellow, green. Here are five smart measurements—and effective ways to present them.”
Metric 1: Baseline Defenses Coverage (Antivirus, Antispyware, Firewall, and so on)
Metric 2: Patch Latency
Metric 3: Password Strength
Metric 4: Platform Compliance Scores
Metric 5: Legitimate E-Mail Traffic Analysis
Source: CSO


