1.

Record Nr.

UNINA9910693840903321

Autore

Swanson Marianne

Titolo

Security metrics guide for information technology systems / / Marianne Swanson [and four others]

Pubbl/distr/stampa

Gaithersburg, Md. : , : National Institute of Standards and Technology, Technology Administration, , 2003

Descrizione fisica

1 online resource

Collana

NIST special publication; NIST special pub; NIST SP

Altri autori (Persone)

SwansonMarianne

Disciplina

535.84

Soggetti

Computer security

Lingua di pubblicazione

Inglese

Formato

Materiale a stampa

Livello bibliografico

Monografia

Note generali

Title from title screen (viewed on June 23, 2004).

Nota di bibliografia

Includes bibliographical references.

Sommario/riassunto

This document provides guidance on how an organization, through the use of metrics, identifies the adequacy of in-place security controls, policies, and procedures. It provides an approach to help management decide where to invest in additional security protection resources or when to research the causes of nonproductive controls. It explains the metric development and implementation process and how it can also be used to adequately justify security control investments. The results of an effective metric program can provide useful data for directing the allocation of information security resources and should simplify the preparation of performance-related reports.