PRAGMATIC Security Metrics: Applying Metametrics to Information Security (Hardcover)
暫譯: 務實的安全指標:將元指標應用於資訊安全 (精裝版)

W. Krag Brotby, Gary Hinson

  • 出版商: Auerbach Publication
  • 出版日期: 2013-01-08
  • 售價: $3,980
  • 貴賓價: 9.5$3,781
  • 語言: 英文
  • 頁數: 512
  • 裝訂: Hardcover
  • ISBN: 1439881529
  • ISBN-13: 9781439881521
  • 相關分類: 資訊安全
  • 立即出貨 (庫存 < 3)

相關主題

商品描述

Other books on information security metrics discuss number theory and statistics in academic terms. Light on mathematics and heavy on utility, PRAGMATIC Security Metrics: Applying Metametrics to Information Security breaks the mold. This is the ultimate how-to-do-it guide for security metrics.

Packed with time-saving tips, the book offers easy-to-follow guidance for those struggling with security metrics. Step by step, it clearly explains how to specify, develop, use, and maintain an information security measurement system (a comprehensive suite of metrics) to help:

  • Security professionals systematically improve information security, demonstrate the value they are adding, and gain management support for the things that need to be done
  • Management address previously unsolvable problems rationally, making critical decisions such as resource allocation and prioritization of security relative to other business activities
  • Stakeholders, both within and outside the organization, be assured that information security is being competently managed

The PRAGMATIC approach lets you hone in on your problem areas and identify the few metrics that will generate real business value. The book:

  • Helps you figure out exactly what needs to be measured, how to measure it, and most importantly, why it needs to be measured
  • Scores and ranks more than 150 candidate security metrics to demonstrate the value of the PRAGMATIC method
  • Highlights security metrics that are widely used and recommended, yet turn out to be rather poor in practice
  • Describes innovative and flexible measurement approaches such as capability maturity metrics with continuous scales
  • Explains how to minimize both measurement and security risks using complementary metrics for greater assurance in critical areas such as governance and compliance

In addition to its obvious utility in the information security realm, the PRAGMATIC approach, introduced for the first time in this book, has broader application across diverse fields of management including finance, human resources, engineering, and production—in fact any area that suffers a surplus of data but a deficit of useful information.

Visit Security Metametrics. Security Metametrics supports the global community of professionals adopting the innovative techniques laid out in PRAGMATIC Security Metrics. If you, too, are struggling to make much sense of security metrics, or searching for better metrics to manage and improve information security, Security Metametrics is the place.

商品描述(中文翻譯)

其他有關資訊安全指標的書籍通常以學術術語討論數論和統計學。《PRAGMATIC Security Metrics: Applying Metametrics to Information Security》打破了這一模式,這是一本關於安全指標的終極實用指南。

本書充滿了節省時間的技巧,為那些在安全指標上掙扎的人提供了易於遵循的指導。逐步清晰地解釋了如何指定、開發、使用和維護一個資訊安全測量系統(即一套全面的指標),以幫助:

- 安全專業人員系統性地改善資訊安全,展示他們所增加的價值,並獲得管理層對需要完成事項的支持
- 管理層理性地解決以前無法解決的問題,做出關鍵決策,例如資源分配和相對於其他業務活動的安全優先級
- 內部和外部的利益相關者確信資訊安全得到了有效管理

PRAGMATIC 方法讓您專注於問題區域,並識別出能夠產生真正商業價值的少數指標。本書:

- 幫助您確定究竟需要測量的內容、如何測量,最重要的是,為什麼需要測量
- 對150多個候選安全指標進行評分和排名,以展示PRAGMATIC方法的價值
- 突出那些廣泛使用和推薦的安全指標,但實際上效果相當差
- 描述創新和靈活的測量方法,例如具有連續尺度的能力成熟度指標
- 解釋如何使用互補指標來最小化測量和安全風險,以在治理和合規等關鍵領域提供更大的保證

除了在資訊安全領域的明顯實用性外,本書首次介紹的PRAGMATIC方法在財務、人力資源、工程和生產等多個管理領域也有更廣泛的應用——事實上,任何面臨數據過剩但有用資訊不足的領域。

訪問Security Metametrics。Security Metametrics支持全球專業人士採用《PRAGMATIC Security Metrics》中提出的創新技術。如果您也在努力理解安全指標,或尋找更好的指標來管理和改善資訊安全,Security Metametrics就是您的最佳選擇。