For Security & Risk Professionals (Length: 11 pages)

May 16, 2007

Defining An Effective Security Metrics Program

by Khalid Kark, Paul Stamp

with Jonathan Penn, Sarah Bernhardt, Alissa Dill

Executive Summary (This is a document excerpt)

In a recent survey, Forrester found that the majority of security metrics programs are still in their infancy or planning phases. The respondents cited two main challenges in developing their metrics programs: finding the right metrics and translating the security metrics into business language. A lot of security managers are focused on gathering and reporting tactical and status update information. To develop a successful security metrics program, CISOs need to identify, prioritize, monitor, and measure security based on business goals and objectives. They should then focus on translating those measurements into business language to help executive management in strategic business decisions.

Buy Risk-Free

Download and print PDF immediately. Price: US $379

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemSecurity Metrics Are Still In Their Infancy

itemSeven Steps To A Successful Metrics Program

recommendations

itemFive Tips On Developing Metrics That Matter With Executives

WHAT IT MEANS

itemMetrics Become The New Justification For Security Investment

Forrester surveyed 19 user companies and interviewed 10 CISOs across all industries, regions, and levels of maturity.

Related Research Documents

itemWhat's Top Of Mind For CISOs In 2007

April 17, 2007, Trends

itemCompliance Optimization: Defining The Right Level Of Control

February 1, 2007, Best Practices

itemDefining A High-Level Security Framework

January 18, 2007, Best Practices

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.
Analyst: Khalid Kark
Technology: Security & Risk
Geography: Asia Pacific, Europe, North America

Upcoming Teleconference:
Jam Session No. 2: (Re)Defining IT Value
Tuesday, December 02, 2008
corner border corner
Ratings and Comments
Rating: 9 out of 10
based on 2 ratings across all roles.
corner border corner