J - SES-602 - Module 10 - Metrics
Computer Networking
11/29/2011

 Practical/useful security metrics have the following basic characteristics:
 • easy to connect to concept of security• transparent data gathering process• supports security decision-making
 What is measurement?
 The process of mapping from theempirical world to the formal, relational world.The measure that results characterizes anattribute of some object under scrutiny. Note: Information Security is not the object, nor awell-understood attribute, which means you are not directly measuring security; you are measuring other things and drawing conclusions about security from them.
 Attributes that can be measured before the outcome is clear.
 Lag Indicators
 Attributes that can only be measured after the fact.
 Key Goal Indicators (KGI)
 Attributes whose measures indicate whether a goal(s) has been met. Since they can only be measured after the fact, they are lag indicators.
 Key Performance Indicators (KPI) or just Performance indicators
 Attributes whose measures indicate whether goals are likely to be met. Since they can be measured before the outcome is clear, they are lead indicators.
 International Standard for Designing/Manageing Security Metrics (Process)
 1. Plan 2. Do 3. Check 4. Act
 Types of measure numbers
 1. Nominal (exists, doesn't exist) 2. Ordinal (order: high, medium, low) 3. Interval (order and quantity) 4. Ratio
 Criteria for Security Metrics (nine things)
 Valid: data supports a hypothesis that system is secureAccurate: data reflects the content of measurement as it was envisionedNumeric: data can be precisely quantifiedCorrect: data is collected according to specificationsConsistent: measure is independent of measurerTime-based: there is a fixed reference point of data collectionReplicable: measurement repeated in same manner in same environment will yield same resultUnit-based: data may be expressed in terms of a unitInformative: data provides information without additional context
 Rules for Evaluation of Metrics
 • Any metric that is not accurate or not valid is weak• Any metric that is accurate and valid is at leastneutral• Any metric that is accurate, valid, informative, andtime-based is strong
 What are the four types of metrics?
 1. Activity 2. Target 3. Remediation 4. Monitor
 Activity Metric (definition)
 Metrics that measure work activity, e.g., incidents reported via email.
 Target Metrics (definition)
 Metrics that have a measurable target (e.g., no missing logs).
 Remediation Metrics (definition)
 Metrics that show progress toward a goal, e.g., % of systems that have been converted to a new operating system.
 Monitor Related Metrics
 Metrics that monitor processes, e.g., the number of changes vs the number of chages authorized, or the percent of password reset call where the staff followed (and/or documented) process.
 Link Indexes to Security Data
 Common Indexes cannot be expected to exist in different realms and different management domains.Expectations for linkage must be articulated.
 Creating/Using Metrics (end to end process)
 • Start with known data on environment• Quantify or otherwise represent unknowns• Link control-relevant data to known data• Anticipate decision requirements• Design presentations for use in decisions
 Risk Assessment Caveats
 Vulnerabilities != ExploitsThreats != ExploitsVulnerabilities + Threats != ExploitsVulnerabilities + Threats allow ExploitsExploits != DamageExploits + Service/Data/Financial Loss = DamageControls minimize probability of Exploits
 Vulnerability
 A weakness which allows an attacker to reduce a system's information assurance. It is the result of a system bug or flaw and must be accessable by an attacker.
 Threat
 A possible danger that might exploit a vulnerability to breach security and thus cause possible harm.
 Exploit
 A piece of software, a chunk of data, or sequence of commands that takes advantage of a bug, glitch or vulnerability in order to cause unintended or unanticipated behavior to occur on computer software, hardware, or something electronic (usually computerised). This frequently includes such things as gaining control of a computer system or allowing privilege escalation or a denial-of-service attack.
 Traditional Risk Assessment Approach
 • Identify Assets within Scope• Determine Threats, Risks, Concerns, andIssues Related to Assets• Prioritize the Risk According to System andInformation Importance• Determine the Threat Level of the Assets• Determine Known Vulnerabilities of theAssets
 Risk Analysis process
 The science of risks and their probability and evaluation.
 Risk Management focuses on the following four areas
 1. Compliance, e.g., total population vs population in compliance. 2. Organizational Structure, e.g., show compliance accross different organizational populations 3. Automation, e.g., automated collection of data 4. Trends (often used to depict data beyond the control of management)
 Redmediation Management focuses on the following:
 1. Quality: Actual number of known vulnerabilities (as opposed to the number of systems scanned for vulnerabilities) 2. Process: control points from process directly correlated to measured activity. 3. Accountability: What was the root cause? 4. Implementation: Recognizes systemic issues and acts.
