NORAD-Inspired Security Metrics
When I was a second degree cadet at USAFA (so long ago that, of my entire class, only myself and three friends had 486 PCs with Ethernet NICs) I visited NORAD . I remember thinking the War Games set was cooler, but I didn't give much thought to the security aspects of their mission. Today I remembered NORAD and considered their mission with respect to my post last year titled Control-Compliant vs Field-Assessed Security . In case you can't tell from the pithy title, the central idea was that it's more effective to measure security by assessing outcomes instead of inputs. For example, who cares if 100% of your systems have Windows XP SP2 if they are all 0wned by a custom exploit written just for your company? Your security has failed. Inputs are important, but my experience with various organizations is that they tend to be the primary means of "measuring" security, regardless of how well they actually preserve the CIA triad. Let's put this in terms of NO...