Web Application Security Metrics
Earlier this year, the Center for Internet Security (CIS) published Consensus Security Metrics to allow organisations to collect, analyse and share data on security performance and outcomes. These are based on the consensus viewpoint of 100 experts.
I've just had a chance to read the whole document and I'm impressed. The document includes twenty consensus metrics definitions for six business functions:
- Incident management
- Vulnerability management
- Patch management
- Application security
- Configuration management
- Financial metrics
Additional metrics for these and other business functions are in development.
The metrics are an excellent reference document and are carefully explained, referenced and excellently presented. These should be of interest to people owning, operating or developing web applications and looking for measures to examine performance, regardless of their role or experience. If you are looking for some metrics, don't re-invent the wheel, read this document first.
Posted on: 13 October 2009 at 09:39 hrs

Comments are filtered automatically and should appear shortly after they been checked.