Security Metrics: Replacing Fear, Uncertainty, and Doubt
暫譯: 安全指標:取代恐懼、不確定性與懷疑

Andrew Jaquith

  • 出版商: Addison Wesley
  • 出版日期: 2007-03-01
  • 售價: $2,520
  • 貴賓價: 9.5$2,394
  • 語言: 英文
  • 頁數: 336
  • 裝訂: Paperback
  • ISBN: 0321349989
  • ISBN-13: 9780321349989
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

商品描述

Description

The Definitive Guide to Quantifying, Classifying, and Measuring Enterprise IT Security Operations

 

Security Metrics is the first comprehensive best-practice guide to defining, creating, and utilizing security metrics in the enterprise.

 

Using sample charts, graphics, case studies, and war stories, Yankee Group Security Expert Andrew Jaquith demonstrates exactly how to establish effective metrics based on your organization’s unique requirements. You’ll discover how to quantify hard-to-measure security activities, compile and analyze all relevant data, identify strengths and weaknesses, set cost-effective priorities for improvement, and craft compelling messages for senior management.

 

Security Metrics successfully bridges management’s quantitative viewpoint with the nuts-and-bolts approach typically taken by security professionals. It brings together expert solutions drawn from Jaquith’s extensive consulting work in the software, aerospace, and financial services industries, including new metrics presented nowhere else. You’ll learn how to:

 

• Replace nonstop crisis response with a systematic approach to security improvement

• Understand the differences between “good” and “bad” metrics

• Measure coverage and control, vulnerability management, password quality, patch latency, benchmark scoring, and business-adjusted risk

• Quantify the effectiveness of security acquisition, implementation, and other program activities

• Organize, aggregate, and analyze your data to bring out key insights

• Use visualization to understand and communicate security issues more clearly

• Capture valuable data from firewalls and antivirus logs, third-party auditor reports, and other resources

• Implement balanced scorecards that present compact, holistic views of organizational security effectiveness

 

Whether you’re an engineer or consultant responsible for security and reporting to management–or an executive who needs better information for decision-making–Security Metrics is the resource you have been searching for.

 

 

Table of Contents

Foreword           xv

Preface             xix

Acknowledgments          xxv

About the Author            xxviii

Chapter 1     Introduction: Escaping the Hamster Wheel of Pain         1

Chapter 2     Defining Security Metrics         9

Chapter 3     Diagnosing Problems and Measuring Technical Security            39

Chapter 4     Measuring Program Effectiveness         89

Chapter 5     Analysis Techniques   133

Chapter 6     Visualization   157

Chapter 7     Automating Metrics Calculations          217

Chapter 8     Designing Security Scorecards            251

Index    301

商品描述(中文翻譯)

**描述**

《量化、分類和測量企業 IT 安全運作的權威指南》

《Security Metrics》是第一本全面的最佳實踐指南,旨在定義、創建和利用企業中的安全指標。

透過範例圖表、圖形、案例研究和實戰故事,Yankee Group 的安全專家 Andrew Jaquith 具體展示如何根據您組織的獨特需求建立有效的指標。您將發現如何量化難以測量的安全活動,彙編和分析所有相關數據,識別優勢和劣勢,設置具成本效益的改進優先事項,並為高層管理層撰寫引人注目的報告。

《Security Metrics》成功地將管理層的定量觀點與安全專業人士通常採取的實務方法相結合。它匯集了 Jaquith 在軟體、航空航天和金融服務行業的廣泛諮詢工作中提煉出的專家解決方案,包括其他地方未曾提出的新指標。您將學會如何:

- 用系統化的方法取代不斷的危機應對,進行安全改進
- 理解「好」指標與「壞」指標之間的差異
- 測量覆蓋範圍和控制、漏洞管理、密碼質量、修補延遲、基準評分和業務調整風險
- 量化安全獲取、實施及其他計畫活動的有效性
- 組織、彙總和分析您的數據,以提煉出關鍵見解
- 使用可視化技術更清晰地理解和傳達安全問題
- 從防火牆和防病毒日誌、第三方審計報告及其他資源中捕獲有價值的數據
- 實施平衡計分卡,提供組織安全有效性的簡潔、整體視圖

無論您是負責安全的工程師或顧問,向管理層報告,或是需要更好資訊以做出決策的高層主管,《Security Metrics》都是您一直在尋找的資源。

**目錄**

前言 xv
序言 xix
致謝 xxv
關於作者 xxviii
第一章 引言:逃離痛苦的倉鼠輪 1
第二章 定義安全指標 9
第三章 診斷問題與測量技術安全 39
第四章 測量計畫有效性 89
第五章 分析技術 133
第六章 可視化 157
第七章 自動化指標計算 217
第八章 設計安全計分卡 251
索引 301

最後瀏覽商品 (20)