Performance Metrics for Information Security Risk Management

Julie J.C.H. Ryan, Daniel J. Ryan · IEEE Security & Privacy · 2008

Qualitative methods are available for risk management, but better practice would use quantitative risk management based on expected losses and related metrics. Measuring the success of information security investments is best accomplished by measuring reductions in expected loss.

Read the paper · More papers on PaperTik