SMotW #4: Control policy compliance
Security Metric of the Week #4: Proportion of critical controls consistent with controls policy This week's security metric example measures the proportion or percentage of critical controls that are consistant or comply with the associated policies. The metric assumes that policies are defined, at least for controls deemed "critical". Arguably, all controls that have documented policies are critical but not necessarily so, and some critical controls may not have policies. Examples of control policies are “access is permitted unless expressly forbidden” and “trust is transitive”. They might also be termed, or be part of, 'control specifications'. If such policies/specifications are not formally defined and mandated, implementation is more likely to be inconsistent and perhaps inappropriate or inadequate. This is a relatively C ostly metric due to the need to assess the consistency or compliance of critical controls with the associated policies. S...