Case Study

Case Study: Verizon Business Builds An Asset-Based Security Metrics Program

July 22nd, 2008
Khalid Kark, null
Khalid Kark
With contributors:
Jonathan Penn , Alissa Dill , Allison Viglianti


In response to the evolving security threat environment and heightened attention to regulatory compliance, many companies started migrating from a purely reactive security program to a proactive risk-based security program. This has led to new challenges for chief information security officers (CISOs), who now need to convert the risk management vision set by the business into an actionable strategy for the security and risk management program. Sara Santarelli, CISO at Verizon Business, started moving her security practice in this direction five years ago when her team was developing an IP risk dashboard that is driven by "asset-based" metrics. Not only does this dashboard measure the effectiveness of the risk management program, but it also translates these measures into an actionable risk mitigation strategy. With asset-based testing and measurements, the results also provide the basis and justification for new security investments and projects.

Want to read the full report?

Contact us to become a client

This report is available for individual purchase ($1495).

Forrester helps business and technology leaders use customer obsession to accelerate growth. That means empowering you to put the customer at the center of everything you do: your leadership strategy, and operations. Becoming a customer-obsessed organization requires change — it requires being bold. We give business and technology leaders the confidence to put bold into action, shaping and guiding how to navigate today's unprecedented change in order to succeed.