Embed presentation
Download as PDF, PPTX







Organizations need business security metrics to understand the costs and value of reducing security risks. Common metrics include the frequency and impact of incidents like unauthorized access, probes, denial of service attacks and viruses. However, organizations often lack data on the impact of incidents and how effective security controls are. To identify appropriate metrics, organizations should determine security goals, ask questions to assess related risks, and identify metrics that help measure progress towards risk reduction goals.






