close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel

Measuring the Effectiveness of Security using ISO 27001

Issuer Full Name
Information Warfare Site (IWS)
Issued
15 July 2006
Type
  • Free/open
Meta Description
Information governance resource reference: Measuring the Effectiveness of Security using ISO 27001
ISO 27001 builds on BS 7799 with much more guidance on information security measurement and metrics. This paper complements the ISO/IEC standard for information security management systems by exploring: 1) security measurement objectives, 2) what security aspects should be measured, in terms of both process and effectiveness; 3) how controls should be measured; 3) how measurements can and should be used to provide "assurance" on the effectiveness?

The paper presents both a ISO 27001-aligned model for security measurement and concrete illustrations of how the model can be applied to demonstrate the effectiveness of security controls in business processes.