The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program, Second Edition

Don't work harder work smarter. Ken Blanchard
This chapter, "Establishing a Metrics Management System," is designed to provide basic guidance necessary for the development of a metrics methodology to understand what, why, when, and how InfoSec can be measured. Using the fictitious company (IWC) and functions that were previously described, a metrics system will be developed. It includes a discussion of how to use the metrics to brief management, justify budget, and use trend analyses to develop a more efficient and effective CIAPP.
Some of the most common complaints ISSOs make are that management doesn't support them, and as the famous comedian Rodney Dangerfield is known for saying "I get no respect." Another complaint is that the cost and benefits of InfoSec cannot be measured.
As for the first two, you get support because you are being paid and these days, more often than not, quite handsomely and you have a budget that could have been part of corporate profits. Furthermore, respect is earned. Besides, if you want to be popular, you are definitely in the wrong profession.
One often hears management ask:
"What is all this security costing me?"
"Is it working?"
"Can it be done at less cost?"
"Why isn't it working?"
That last question often comes right after a successful denial of service attack or some other attacks on the corporate systems or Web sites. Of course, many ISSOs respond by saying that it can't be measured. That is often said out of the ISSO's ignorance of processes to...