The document outlines the development of actionable security metrics to protect enterprises, emphasizing the importance of specific, relevant, and repeatable metrics aligned with business goals. It discusses different types of metrics, including leading, lagging, and coincident indicators, and critiques existing metrics for their limited correlation with vulnerabilities and attacks. Additionally, it highlights common industry metrics, limitations, and proposes new metrics for assessing security based on real-world data.
Related topics: