METRICS/BUDGETS Articles
Security metric techniques: How to answer the 'so what?'
You need to be ready when the boss responds to your presentation with a "so what?" At Metricon 5, the focus is on several security metric techniques to pull it off.
IT risk assessment frameworks: real-world experience
Formal risk assessment methodologies try to take guesswork out of evaluating IT risks. Here is real-world feedback on four such frameworks: OCTAVE, FAIR, NIST RMF, and TARA.
Maley: Here's How Firing REALLY Went Down
Former State of Pennsylvania CISO Robert Maley says there's been a lot of misinformation about his firing. At CSO Perspectives 2010, he sought to clarify things.
Security Consultants and Lawyers: Don't Trust Them to Manage Risks
Security consultant Scott Wright breaks down the similarities between attorneys and consultants -- and explains why neither can really give you the risk management you need
RSA 2010: Infosec Pros Get Raises Despite Recession
An (ISC)2 survey suggests salary increases and hiring went up for many security practitioners in the last year despite the Great Recession. Ironically, the recession may be WHY it's happening.
Security visualization hardware and software
An emerging discipline
Physical Security Risk and Countermeasures: Effectiveness Metrics
Is your security program working? Here's how to establish metrics for systematic measurement and improvement.
Physical Security Risk and Countermeasures: Information Requirements
What information does a security manager need in order to select countermeasures? Thomas Norman spells out the details.
Companies on IT Security Spending: Where's the ROI?
Companies have spent millions to bolster their IT security in recent years. But some are starting to wonder if it's been worth it, according to the 2010 Cyber Security Watch survey CSO conducted with the U.S. Secret Service, Carnegie Mellon University CERT and Deloitte & Touche.
Clear Metrics for Cloud Security? Yes, Seriously
In the second installment of his series on "Clearing the Cloud," security expert Ariel Silverstone proposes some clearer definitions and metrics to improve cloud security.
