The Cybersecurity Resilience Quotient Measuring Security Effectiveness
The truth is that in today’s hyperconnected world, maturity-based cybersecurity programs are no longer adequate for combatting cyberrisks. A more strategic, risk-based approach is imperative for effective and efficient risk management (Exhibit 2).
Jim Boehm • The Risk-Based Approach to Cybersecurity
Andress leans on the FAIR standard from the FAIR Institute to create metrics to share. FAIR stands for Factor Analysis of Information Risk , described as **“**the only international standard quantitative model for information security and operational risk.”
CSO Online • Better Metrics Can Show How Cybersecurity Drives Business Success
For example: if you can pick 20 metrics that encapsulate a number of the CIS Critical Controls and work like crazy to keep your environment to those then you will likely get more benefit than spending your time on more sophisticated approaches.
Phil Venables • 6 Truths of Cyber Risk Quantification
Mostly, they seek out vulnerabilities, detect attacks, and eliminate compromises. Of course, the size of the attack surface and the sheer volume of vulnerabilities, attacks, and compromises means organizations must make tough choices; not everything gets fixed, stopped, recovered, and so forth. There will need to be some form of acceptable (tolerab
... See more