开发工具:
文件大小: 569kb
下载次数: 0
上传时间: 2020-02-18
详细说明:The requirement to measure information technology (IT) security performance is driven by
regulatory, financial, and organizational reasons. A number of existing laws, rules, and
regulations cite IT performance measurement in general, and IT security performance
measurement in particular, as a requirement. These laws include the Clinger-Cohen Act,
Government Performance and Results Act (GPRA), Government Paperwork Elimination Act
(GPEA), and Federal Information Security Management Act (FISMA).
This document is intended to be a guide for the specific development, selection, and
implementation of IT system- level metrics to be used to measure the performance of information
security controls and techniques.1 IT security metrics are tools designed to facilitate decision
making and improve performance and accountability through collection, analysis, and reporting
of relevant performance-related data. This document provides guidance on how an organization,
through the use of metrics, identifies the adequacy of in-place security controls, policies, and
procedures. It provides an approach to help management decide where to invest in additional
security protection resources or identify and evaluate nonproductive controls. It explains the
metrics development and implementation processes and how metrics can be used to adequately
justify security control investments. The results of an effective IT security metrics program can
provide useful data for directing the allocation of information security resources and should
simplify the preparation of performance-related reports. Successful implementation of such a
program assists agencies in meeting the annual requirements of the Office of Management and
Budget (OMB) to report the status of agency IT security programs.
(系统自动生成,下载前可以参看下载内容)
下载文件列表
相关说明
- 本站资源为会员上传分享交流与学习,如有侵犯您的权益,请联系我们删除.
- 本站是交换下载平台,提供交流渠道,下载内容来自于网络,除下载问题外,其它问题请自行百度。
- 本站已设置防盗链,请勿用迅雷、QQ旋风等多线程下载软件下载资源,下载后用WinRAR最新版进行解压.
- 如果您发现内容无法下载,请稍后再次尝试;或者到消费记录里找到下载记录反馈给我们.
- 下载后发现下载的内容跟说明不相乎,请到消费记录里找到下载记录反馈给我们,经确认后退回积分.
- 如下载前有疑问,可以通过点击"提供者"的名字,查看对方的联系方式,联系对方咨询.