Tuesday, 25 December 2007

Performance Measurement for Information Security

Although measuring information security performance is required by law in USA such as the Clinger-Cohen Act, the Government Performance and Results Act (GPRA), the Government Paperwork Elimination Act (GPEA), and the Federal Information Security Management Act (FISMA). Also, I do believe that the driven factor for any thing is the business need or monetary value.

What do we need to measure for Information Security?

NIST specified three measure types which are:

  1. Execution of security policy.
  2. Effectiveness/efficiency of security services delivery.
  3. Impact of security events.

Performance Measurement for Information Security Challenges:

  • Inconsistent process, when you try this kind of process you will find it challenge to specify your performance targets to measure.
  • Identifying the goals and objectives of performance management. The best start will be from business/stakeholder interest.
  • Establishing Performance Targets. Setting performance targets for effectiveness/efficiency and impact measures is more complex because there isn’t a specific level of performance.

What do we need to implement this Performance Measurement?

  1. Collecting data.
  2. Analyze collecting data.
  3. Identify Corrective Actions.
  4. Develop Business Case.
  5. Apply Corrective Actions.

By building Performance Measurement for Information Security we facilitate decision making and improve effectiveness/efficiency of information security service delivery.

Reference: NIST & ISF “Security Health check Project”

No comments: