Posts

Showing posts with the label SMotQ

PRAGMATIC Security Metric of the Quarter #7

Image
PRAGMATIC Information Security Metric of the Seventh Quarter According to the overall PRAGMATIC scores assigned by ACME's managers, the latest metric discussed was the top choice in the three months just past, but it was a close-run thing: Example metric P R A G M A T I C Score Information security incident management maturity 90 95 70 80 90 85 90 85 90 86% Information security ascendancy 97 87 15 94 86 90 99 97 99 85% Quality of system security 83 88 83 73 90 68 80 82 10 73% Integrity of the information asset inventory 82 66 83 78 80 43 50 66 70 69% Proportion of systems security-certified 72 79 73 89 68 32 22 89 88 68% Number of different controls 71 75 72 75 88 30 50 65 43 63% Controls consistency 78 83 67 60 71 33 27 31 27 53% Value of information assets owned by each Information Asset O...

PRAGMATIC Security Metric of the Quarter #6

Image
The league table for another 3-month's information security metrics shows a very close race for the top slot: Metric P R A G M A T I C Score Power consumed by the computer suite versus air conditioning capacity 81 69 89 92 80 99 98 90 98 88% Security governance maturity 95 97 70 78 91 89 90 85 90 87% Business continuity plan maintenance status 75 75 90 73 84 76 80 77 93 80% Number or proportion of security policies addressing viable risks 65 76 91 73 83 77 70 61 78 75% Quality of security policies 80 85 40 66 72 75 80 80 80 73% Number of controls meeting defined control criteria or objectives 88 86 88 65 78 60 26 90 70 72% Corporation's economic situation 72 80 10 80 80 80 61 80 79 69% % of highly privileged or trusted users or functions 86 80 51 40 65 39 55 95 60 63% ...

PRAGMATIC Security Metric of the Quarter #5

Image
Example Information Security Metric of the Fifth Quarter The PRAGMATIC scores for another 3-month's worth of information security metrics examples are as follows: Example metric P R A G M A T I C Score Information access control maturity 90 95 70 80 90 80 90 85 90 86% Security policy management maturity 90 95 70 80 88 85 90 82 88 85% Number of important operations with documented & tested security procedures 95 96 91 85 95 84 62 90 60 84% Information security budget variance 70 90 85 77 80 77 80 90 95 83% % of information assets not [correctly] classified 75 75 97 85 90 80 80 80 80 82% Policy coverage of frameworks such as ISO/IEC 27002 70 75 90 69 85 76 72 65 85 76% % of policy statements unambiguously linked to control objectives 92 91 64 60 85 65 45 75 75 72% Rate of change of emerge...

PRAGMATIC Security Metric of the Quarter #3

Image
PRAGMATIC Security Metric of the Third Quarter These are the example information security metrics we have discussed and scored over the past three months, ranked in descending order of their PRAGMATIC scores:  Example metric P R A G M A T I C Score Metametrics 96 91 99 92 88 94 89 79 95 91% Access alert message rate 87 88 94 93 93 94 97 89 79 90% Asset management maturity 90 95 70 80 90 85 90 85 90 86% Compliance maturity 90 95 70 80 90 85 90 85 90 86% Physical security maturity 90 95 70 80 90 85 90 85 90 86% Thud factor 82 80 60 60 70 45 85 86 84 72% Business continuity spend 75 92 20 82 95 70 70 70 70 72% Benford's law 84 30 53 95 11 98 62 98 23 62% Controls coverage   87 89 65 40 74 35 46 40 30 56% Homogeneity 67 70 40 59 67 50 ...