Issue No. 05 - September/October (2008 vol. 6)
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2008.125
Julie J.C.H. Ryan , George Washington University
Daniel J. Ryan , National Defense University
Qualitative methods are available for risk management, but better practice would use quantitative risk management based on expected losses and related metrics. Measuring the success of information security investments is best accomplished by measuring reductions in expected loss.
risk management, information security, security and protection, security metrics
J. J. Ryan and D. J. Ryan, "Performance Metrics for Information Security Risk Management," in IEEE Security & Privacy, vol. 6, no. , pp. 38-44, 2008.