Metrics tell you and your stakeholders whether the information security program is working. Without them, the program cannot show value, justify budget or spot problems early, and decisions are made on opinion rather than evidence. The challenge is not collecting numbers, which security tools produce in huge volumes, but choosing measures that answer real questions for each audience and lead to action.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.