The Cybersecurity Resilience Quotient Measuring Security Effectiveness
The truth is that in today’s hyperconnected world, maturity-based cybersecurity programs are no longer adequate for combatting cyberrisks. A more strategic, risk-based approach is imperative for effective and efficient risk management (Exhibit 2).
Jim Boehm • The Risk-Based Approach to Cybersecurity
Andress leans on the FAIR standard from the FAIR Institute to create metrics to share. FAIR stands for Factor Analysis of Information Risk , described as **“**the only international standard quantitative model for information security and operational risk.”
CSO Online • Better Metrics Can Show How Cybersecurity Drives Business Success
For example: if you can pick 20 metrics that encapsulate a number of the CIS Critical Controls and work like crazy to keep your environment to those then you will likely get more benefit than spending your time on more sophisticated approaches.