Educause Security Discussion mailing list archives

SA Evaluation, Metrics and Benchmark


From: Melissa Guenther <mguenther () COX NET>
Date: Thu, 13 May 2004 08:23:19 -0700

 Attached is the information I was able to put together as a result of the
many responses I received (from both national and international
contributors).
 Question - Why is security awareness typically such a failure?  It is
mentioned in 3 places in the 7799 spec.  It is usually considered only
slightly less important than policy.  Yet, it seems to be uniformly poorly
implemented.
 

I was surprised as to how much information I received in regards to metrics.
 Iput an emphasis on that.  I "smurgled" some information with tools I have
esigned and use frequently for benchmarking and measurement.  The preface
ays it all - I hope to hear from you as you move ahead with your SA efforts


Thank you to all that contributed. 

Kindest regards 
Melissa 

 
Melissa Guenther
Increasing awareness to Improve Security
480-786-6034

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Attachment: Evaluation metrics and benchmark security awarness1.doc
Description:


Current thread: