Security Process Maturity: Level 5
Security managers are often plagued by the question, “How do I make security measurable?” Since security does not produce a product or have a positive impact on the cash flow of a company, creating meaningful measurements that justify an organizations expenditure on security is challenging. This is where ISM3 provides a great tool for measuring security.
ISM3's level five is about taking all of the processes of levels one through four and using them to communicate the coverage and effectiveness of security.
ISM3 defines seven types of metrics that work well within this maturity model:
Process Metrics
Performance Metrics
Measuring each of the ISM3 processes implies that there is a system that easily captures metrics as part of normal operation. Without a centralized metrics reporting system, ISM3 level five will be unsustainable.
The most important reason for measuring your security processes is to identify how well you are operating and work on continuous improvement. At this level, managing the process of continuous improvement is important. By measuring, automating, improving, and communicating your security metrics, you will create a sustainable, continuously improving security operation.
Labels: Security Process




0 Comments:
Post a Comment
Links to this post:
Create a Link
<< Home