Skip to main content

Metrics-driven information security framework as part of information security management

As part of any Information Security Management System, measuring and reporting information security should be a top priority. However, there are no ready-made models or recommended metrics on how this should be done. The status, success, and posture of information security are in many cases measured and developed based on gut instinct, intuition, and the know-how of the information security team. This paper presents a model of creating an actual accurate metrics-based security reporting model that is tied closely to the security management model used at the company. This will provide the top management with relevant and factual data on the information security posture of the company and the information security leader tools and methods to elevate the importance of information security as part of the top management agenda.

sans-metrics-driven-information-security-framework-as-part-of-information-security-management (PDF, 0.33MB)

22 Mar 2022
ByKirill Filatov
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.

Metrics-driven information security framework as part of information security management