Chapter 10

Establishing a Metrics Management System

Abstract

This chapter is designed to provide basic guidance necessary for the development of a metrics methodology to understand what, why, when, and how a cyber security program can be measured. Using a fictitious corporation and functions that were previously described, a metrics system will be developed. The chapter includes a discussion of how to use the metrics to brief management, justify budget, and use trend analyses to develop a more efficient and effective cyber security program.

Keywords

Corporate information officer (CIO); Cost-avoidance metrics; Cyber security program metric; Education and awareness training program (EATP); Metrics charts; Metrics management; Project chart; Stand-alone ...

Get The Information Systems Security Officer's Guide, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.