"A few well-chosen metrics can be a huge help in monitoring controls and measuring their effectiveness"

Clint Kreitner · 2008

Summary This paper discusses a range of potential targets and metrics to improve the management of information security controls and risks. We are not suggesting that all of these are necessary or appropriate for any organization, rather that management should consider the suggestions and then select ‘a few good metrics’ to use as part of the overall corporate management framework for information security.

Read the paper · More papers on PaperTik