Metrics for Information Security - A literature review
Raj Sharman, H. Raghav Rao, Shambhu Upadhyaya · Journal of the Association for Information Systems · 2004
It is important to know how vulnerable systems are for a wide variety of reasons.Information Systems managers have the duty to advise senior management of the level of risks faced by the information systems.Therefore an assessment of the level of risk is necessary.Research work in this area is in its infancy.Further, the efforts are varied and deal with different aspects of the issue.There is no coherent approach.This paper provides a review of the literature and will be presenting a framework for analysis and development of metrics for security at the conference..