Security Metrics – the “new” topic?
NIST recently released an overview report on the current state of research in security metrics (short story: there are almost none), and some areas where they feel more research is warranted. One of the problems with security as a business process is that managers are being taught process improvements is the way to save money, but with security, there are no obvious metrics to measure to improve the process. Security is subjective, based on the person and the situation, and measurements tend to the objective side of things.
I think that seeing new measurements is really going to improve the overall security landscape – once they’re accepted and used. NIST and the Feds already kind of lead the way with FIPS and Common Criteria (European based), and I think that if they start using a particular metric, the commercial world will follow. One of the detriments to security metrics is that until the last few years, it hasn’t been well studied in universities – the “hotbeds” of research. I think that now we may start to see more metrics coming out as more graduate students start to study it. And if you happen to be a current grad student interested in security metrics, the NIST paper has some great starting points for a thesis.

November 14th, 2009 at 9:11 am
Question on congratulations?
July 10th, 2010 at 1:36 am
I don’t know how good netbooks are and would like to know if one such as the DELL Inspiron Mini 10v Netbook would be powerful enough to support a program such as microsoft word? many thanks
______________
Przepisy na ciasta
August 8th, 2010 at 11:13 am
Impossible to give you a time frame. If you take care of it, it may last you a long time.
_________________
Tapety na pulpit