<?xml version="1.0" encoding="utf-8"?><!-- generator="wordpress/2.0.5" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Let the  Metrics Begin!</title>
	<link>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/</link>
	<description>We are the people your IT department warned you about</description>
	<pubDate>Fri, 12 Mar 2010 01:27:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.5</generator>

	<item>
		<title>by: Chandler Howell</title>
		<link>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-180105</link>
		<pubDate>Tue, 08 Jan 2008 13:11:43 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-180105</guid>
					<description>Ian,

Don't worry...I'm definitely thinking hard about how best to measure both traditional perimeter effectiveness as well as thinking about how to evaluate the trade-off's that deperimeterization brings.  The challenge is getting over the "so what?" hump from operational to true KPI's.

Also, I knew from Alex Hutton and the rest of the team at &lt;a href="http://riskmanagementinsight.com" rel="nofollow"&gt;Risk Management Insight&lt;/a&gt; that FAIR was under the Open Group's aegis.</description>
		<content:encoded><![CDATA[<p>Ian,</p>
<p>Don&#8217;t worry&#8230;I&#8217;m definitely thinking hard about how best to measure both traditional perimeter effectiveness as well as thinking about how to evaluate the trade-off&#8217;s that deperimeterization brings.  The challenge is getting over the &#8220;so what?&#8221; hump from operational to true KPI&#8217;s.</p>
<p>Also, I knew from Alex Hutton and the rest of the team at <a href="http://riskmanagementinsight.com" rel="nofollow">Risk Management Insight</a> that FAIR was under the Open Group&#8217;s aegis.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ian Dobson</title>
		<link>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-179567</link>
		<pubDate>Mon, 07 Jan 2008 16:49:46 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-179567</guid>
					<description>Chandler,

You've certainly chosen a challenging area. Yes - gathering measurements is not really the problem. The hard part is using meaningful metrics meaningfully, so they build a credible picture on the performance and effectiveness of the thing you're measuring. This in turn requires a measurement model which delivers sound, objective, consistent results. I'll look forward following your reports on progress, not least as valuable contributions to our Risk Management project (FAIR - http://www.opengroup.org/projects/security/doc.tpl?CALLER=index.tpl&#38;gdid=13231). 

Regards,
Ian Dobson.</description>
		<content:encoded><![CDATA[<p>Chandler,</p>
<p>You&#8217;ve certainly chosen a challenging area. Yes - gathering measurements is not really the problem. The hard part is using meaningful metrics meaningfully, so they build a credible picture on the performance and effectiveness of the thing you&#8217;re measuring. This in turn requires a measurement model which delivers sound, objective, consistent results. I&#8217;ll look forward following your reports on progress, not least as valuable contributions to our Risk Management project (FAIR - <a href="http://www.opengroup.org/projects/security/doc.tpl?CALLER=index.tpl&amp;gdid=13231" rel="nofollow">http://www.opengroup.org/projects/security/doc.tpl?CALLER=index.tpl&amp;gdid=13231</a>). </p>
<p>Regards,<br />
Ian Dobson.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Chandler Howell</title>
		<link>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-179480</link>
		<pubDate>Mon, 07 Jan 2008 13:40:08 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-179480</guid>
					<description>Erik,

Thanks for that pointer.  The library seems to be fairly preliminary for now (not a criticism--everything has to start somewhere), but it's certainly an interesting starting point and I'll be sure to add my own KPI's as we select them.</description>
		<content:encoded><![CDATA[<p>Erik,</p>
<p>Thanks for that pointer.  The library seems to be fairly preliminary for now (not a criticism&#8211;everything has to start somewhere), but it&#8217;s certainly an interesting starting point and I&#8217;ll be sure to add my own KPI&#8217;s as we select them.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Erik Hoffmann</title>
		<link>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-179407</link>
		<pubDate>Mon, 07 Jan 2008 09:47:47 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/01/04/let-the-metrics-begin/#comment-179407</guid>
					<description>Chandler, 

it will be interesting to see what kind of metrics you will define. Perhaps http://www.kpilibrary.com can give some inspiration and input, although i think the IT security categories could benefit from your experience and participation:

http://kpilibrary.com/?cat=145
http://kpilibrary.com/?cat=95

best regards.</description>
		<content:encoded><![CDATA[<p>Chandler, </p>
<p>it will be interesting to see what kind of metrics you will define. Perhaps <a href="http://www.kpilibrary.com" rel="nofollow">http://www.kpilibrary.com</a> can give some inspiration and input, although i think the IT security categories could benefit from your experience and participation:</p>
<p><a href="http://kpilibrary.com/?cat=145" rel="nofollow">http://kpilibrary.com/?cat=145</a><br />
<a href="http://kpilibrary.com/?cat=95" rel="nofollow">http://kpilibrary.com/?cat=95</a></p>
<p>best regards.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
