Quick thought for the day. Most technologies in the security world move through a predictable cycle of adoption. First an organization implements a solution to gain visibility into the scope of the problem (VA, IDS, DLP/CMF, SIEM) then once it becomes apparent that the problem is vast and overwhelming they move to operationally implement technical [...]
Posts Tagged ‘Risk’
Moving Security through Visibility to Implementing Operational Controls
Posted in Security, tagged Auditing, BigFix, cloud computing, Gartner, IDS, Intrusion detection, Intrusion prevention, IPS, McAfee, Monitoring, nCircle, network security, Risk, threats, Virtualization, vulnerabilities, Vulnerability Assessment on December 22, 2008 | 1 Comment »
5 Security Metrics That Matter
Posted in Security, tagged Metrics, Risk, Security on April 24, 2008 | 2 Comments »
Security metrics, which I have posted on in the past (here), and (here), are almost as elusive as security ROI. But unlike the mystical pink unicorn that is security ROI, security metrics are real, tangible and meaningful. Why is it then that we have so much difficulty in defining metrics that are both simple in [...]



