Edward Ferrara serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
New Research: Develop Effective Security Metics - Published this Month
Posted by Edward Ferrara on January 23, 2012
- 265 Recommendations
- 0 comments
This month I published a new report on information security metrics, best practices as well as a maturity model to measure your maturity in the reporting process. This report outlines the future look of Forrester's solution for security and risk (S&R) professionals looking to build a high-performance security program and organization. We designed this report to help S&R pros develop and report the appropriate security metrics for their security organization. Security metrics are a key initiative for chief information security officers (CISOs) today, but many struggle with picking the right metrics. Some CISOs use a broad-brush approach, using operational metrics to demonstrate security. The problem with this approach is that most people don't understand what the metrics are saying, and they don't understand how these metrics make their lives easier or harder. Good metrics are easy-to-understand, incite actions, and change behavior by providing a clear idea of why the audience cares. When CISOs present metrics, they must be able to clarify "What it means" and "What's in it for me?" Use this paper as a set of guidelines to develop a well-formed security metrics strategy and to drive behavior change and improve performance.
Take a look at these links:
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (20)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- Information Security (4)
- Managed Security Services (2)
- Revenue and Growth (2)
- The Value of Data (2)
- business value (1)
- Creating Business Value (1)
- Data privacy (1)
- endpoint security (1)
- enterprise architecture (1)
- Managed Services (1)
- See all
Archives
- May 2013 (1)
- October 2012 (3)
- August 2012 (2)
- July 2012 (1)
- May 2012 (1)
- April 2012 (2)
- February 2012 (1)
- January 2012 (1)
- December 2011 (1)
- October 2011 (2)
- June 2011 (1)
- May 2011 (2)
- April 2011 (2)