Techniques for enterprise network security metrics

  • Authors:
  • Anoop Singhal;Xinming Ou

  • Affiliations:
  • National Institute of Standards and Technology, Gaithersburg, Maryland;Kansas State University, Manhattan, Kansas

  • Venue:
  • Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

Currently, it is difficult to answer simple questions such as "are we more secure than yesterday" or "how should we invest our limited security resources." Decision makers in other areas of business and engineering often use metrics for determining whether a projected return on investment justifies its costs. Spending for new cyber-security measures is such an investment. Thus security metrics that can quantify the overall risk in an enterprise system are essential in making sensible decisions in security management.