SMotW #33: thud factor
Security Metric of the Week #33: thud factor, policy verbosity index, waffle-o-meter If you printed out all your security policies, standards, procedures and guidelines, piled them up in a heap on the table and gently nudged it off the edge, how much of a thud would it make? 'Thud factor' is decidedly tongue-in-cheek but there is a point to it. The premise for his metric is that an organization can have too much security policy material as well as too little. Excessively lengthy, verbose, confusing and/or overlapping policies are less likely to be read, understood and complied-with, while compliance and enforcement would also be of concern for excessively succinct, narrow and ambiguous policies. A scientist might literally measure the thud using an audio sound level meter, dropping the materials (stacked/arranged in a standard way) from a standard height (such as one metre) onto a standard surface (such the concrete slab of the laboratory floor), getting a...