“Any activity cannot be managed if it cannot be measured…” One of the things I love about this is, this is like a striking quote! Conveys a lot of message in a single sentence and I believe it is true.

Shirley C Payne writes about ‘Security Metrics’ at Sans.org, a highlevel guide for an approach of process-definition of how it can be started off. Any company can start a program like this if you really care about your management since it gives you the measurement.

[Click to redirect to the article]