Visible to the public Designing Good Security Metrics

TitleDesigning Good Security Metrics
Publication TypeConference Paper
Year of Publication2019
AuthorsYee, George O. M.
Conference Name2019 IEEE 43rd Annual Computer Software and Applications Conference (COMPSAC)
Date Publishedjul
PublisherIEEE
ISBN Number978-1-7281-2607-4
Keywordsdesigning, Firewalls (computing), good security metric, good security metrics, Human Behavior, Measurement, Measurement and Metrics Texting, Metrics, metrics testing, Organizations, policy-based governance, pubcrawl, resilience, Resiliency, security metrics, security of data, security weaknesses, Software, Standards organizations, step-by-step method, Testing, weaknesses
Abstract

This paper begins with an introduction to security metrics, describing the need for security metrics, followed by a discussion of the nature of security metrics, including the challenges found with some security metrics used in the past. The paper then discusses what makes a good security metric and proposes a rigorous step-by-step method that can be applied to design good security metrics, and to test existing security metrics to see if they are good metrics. Application examples are included to illustrate the method.

URLhttps://ieeexplore.ieee.org/document/8754182
DOI10.1109/COMPSAC.2019.10270
Citation Keyyee_designing_2019