Monday February 01, 2010 - 12pm ET / By Leonel Navarro, Project Management Professional
Register to webinar
Content
|
|
The most important goal of an application security (appsec) program is to secure the organization’s information assets, and maintain the security infrastructure breach-free. A successful program is hardly a one-time project, but rather an on-going effort that constantly provides education, guidance and tools. The only way to really understand how such a program is working is through the implementation of an effective performance tracking system that is supported by the right metrics.
The appsec program starts with a comprehensive application vulnerability detection strategy, as discussed in a previously published whitepaper, and requires the right mechanisms to measure its ability to meet the following objectives:
In this document we’ll share six conditions we have identified as essential for establishing a solid path that enables a metrics-driven application security program, one that allows for the transformation of data into reliable, accurate and precise information.
1. Understand the different types of threats
2. Identify key performance indicators (KPIs) and define SMART metrics
3. Establish a well-defined and measurable process
4. Rate vulnerabilities within the appropriate context
5. Create a vulnerability tracking system
6. Make metrics visible to management