Posts

New security metrics discussion group

Image
One of several competing interests that keeps me away from this blog is the new LinkedIn group " Security Metametrics ".  In setting it up as a moderated forum, Krag Brotby and I intend to keep the discussions focused on security metrics, specifically, hopefully excluding the banal and off-topic marketing drivel and job ads that infest other groups, decimating the signal-to-noise ratio (hence you may occasionally catch me referring tongue-in-cheek to "LinkeDin"). It's early days for the group but so far we have introduced both the PRAGMATIC method and the concept of metametrics , and discussed some of the reasons why security metrics are not yet widely used. I have cross-posted a couple of our 'Security Metric of the Week' pieces from the Security Metametrics blog and I am looking forward to your feedback on the example metrics, the  PRAGMATIC  approach, our book and so forth. Everyone with a genuine interest in metrics is most welcome to join the gr...

SMotW #82: non-financial impacts

Image
Security Metric of the Week #82: non-financial impacts of information security incidents You may genuinely believe that "In the end, it all comes down to money" and, in respect of our capitalist society and commercial organizations at least, you have a point. Money is the near-universal unit of measurement, valuation and comparison, undoubtedly an important parameter. However, "There's more to life than money" and more at stake than simply returning a profit.  This metric attempts to measure the broader effects of information security incidents, other than their financial impacts.  Consider the following examples to understand what the metric might attempt to measure: In addition to the financial costs and penalties arising from privacy breaches, individuals' personal interests and wellbeing are harmed, corporate reputations and brands suffer, and society as a whole is impoverished by the erosion of trust; When government departments and non-profit organizat...

Social engineering: beyond awareness

Image
Social engineering is the topic of our latest security awareness module, delivered to customers over the weekend.  Given that awareness is a means to an end, not an end in itself, we took the trouble to explain what social engineering is and how to respond if employees think they might be being socially engineered - in other words both informing and motivating them to behave differently. Picking up on a suggestion from DEFCON 2013 to encourage critical thinking , the awareness materials aim to get people to think about what they are being asked before responding. Simply knowing that the requester might not be who they claim to be, and that the request might not be legitimate or appropriate, could be all it takes to avoid falling for a scam. The trick is first to learn how typical social engineering attacks take place, and then to recognize the warning signs, the red flags as we call them - but even that is not enough: employees need to know what to do next if they spot the red fla...

SMotW #81: control count

Image
Security Metric of the Week #81: number of different information security controls We're not entirely sure why anyone would feel the need to count their security controls, unless perhaps they think there might either be too many or too few, begging the question "How many controls  should we have?". Nevertheless, somebody proposed this as an information security metric and  ACME's managers explored, discussed and scored it through  the  PRAGMATIC  process : P R A G M A T I C Score 71 75 72 75 88 30 50 65 43 63% They felt that counting security controls would be tedious, error-prone and laborious hence the metric's depressed ratings for T imeliness, A ccuracy and C ost-effectiveness. The 88% rating for M eaningfulness suggests that they believed this metric would provide useful information, provided the following issues were addressed. The word "different" in the full title of the metric could be misle...

Roughly right trumps precisely wrong

Image
Inspired by a rant against information overload , I looked up Sturgeon's Law  which might be paraphrased as "90% of everything is crap".  That in turn got me thinking about the Pareto principle (a.k.a. the 80/20 rule: 80% of the effects relate to 20% of the causes). The numbers in both statements are arbitrary and indicative, not literal. The 80% or 90% values are meant to convey "a large proportion" and bear no special significance beyond that. Adding the phrase "of the order of" would not materially affect either statement.   I'm also reminded that (according to Stephen Wright) "42.7% of statistics are made up on the spot", while Benjamin Disraeli's  " lies, damned lies, and statistics " reminds us that numbers can be used to mislead as much as to inform. So how does this relate to  PRAGMATIC   security metrics ? It is especially pertinent to the A ccuracy and  M eaningfulness criteria. Most metrics can be made more  A cc...

PCI, meet Security Awareness

Image
Whereas current and previous versions of PCI DSS, the standard for securing credit card data, have mentioned the need for security awareness, the forthcoming PCI 3.0 release will be more forthright on the need for security education and awareness. According to the  official change notice , “Lack of education and awareness around payment security, coupled with poor implementation and maintenance of the PCI Standards, gives rise to many of the security breaches happening today. Updates to the standards are geared towards helping organizations better understand the intent of requirements and how to properly implement and maintain controls across their business. Changes to PCI DSS and PA-DSS will help drive education and build awareness internally and with business partners and customers.” The underlying issue is that, without adequate awareness, other information security controls are more or less pointless. I suspect PCI 3.0 will focus on ensuring that PCI security requirements are v...

On being cast adrift in a sea of metrics

Image
With a spot of brainstorming and Googling around , it's not hard at all to come up with hundreds of candidate security metrics, often in fact entire families of potential metrics based on any starting point such as the 150 metrics in our book  (we'll show you how that works with our next 'example metric of the week', here on the blog). There are loads of information-security-related things that could be measured, and loads of ways to measure them. This is a point we discussed in chapter 3, describing many potential sources of metrics inspiration.  If you don't perceive a vast ocean of possible security metrics before you, you're either lacking in experience or you need to look harder! Having come up with a big bunch of possible security metrics, the PRAGMATIC method is a great way to filter out the few that are actually worth putting into production. Metrics with relatively low PRAGMATIC scores naturally gravitate to the bottom of your list while the high-ach...