A CISO’s Guide to an Effective Cybersecurity Metrics Program
This briefing is based on the findings of a cross-sector task force of CISOs and staff who shared their challenges and best practices for developing and using security metrics to drive decisions within their organizations. Topics discussed include: (1) defining security metrics; (2) identifying criteria for an effective security metric; (3) adopting a metrics framework; (4) methods for metrics reporting and decision-making; (5) guidance for initiating a metrics program; (6) strategies for expanding the program; and (7) tools members use to collect and report metrics. Supporting tools that will be shown during the briefing including the Security Metrics Selection Compendium, which includes a self-assessment for assessing controls maturity and selecting metrics, Top 20 “must measure” metrics, and links to references that contain supporting metrics. Please join members of the Task Force as they share visuals and key insights to help you improve the effectiveness of your Cybersecurity Metrics Program. Speakers: • Arlan McMillan, CISO, Kirkland & Ellis LLP (Executive Sponsor) • Mark Brashear, Security Operations Manager, Illinois Tool Works • Jeff Morgan, Associate Director • Humana Scott Schmuhl, CISO, Merrick Bank • Alexandra Zafra, CISO, Intercept Pharmaceuticals

How To Manage Security Risks & Threats | Google Cybersecurity Certificate

The First 6 Months as a CISO Determines Success or Failure

Effective Cybersecurity Policies for AI and Emerging Technologies

The 20 Critical Security Controls: From Framework to Operational to Implementation

ISO ISO 27001:2022 Certification: What You Need to Know

GME Core Curriculum Series: Quality Improvement in Action

3-19-25 Building and Finance Subcommittee

Top Five Trends in CISO Leadership

Scarce Resources, Smarter Investments: How Outcomes Based Contracting Can Help States and Districts

A CISO’s Guide to Harnessing the Power and Managing the Risks of Artificial Intelligence (AI)

Overview of Zero Trust Architectures

Building a Resilient Workforce: Strategies to Prevent Single Points of Failure

Key Risk Indicators for Effective Strategy Management

A case study master class on Reporting Cyber Risk to the Board by Omar Khwaja

4-8-24 Building & Finance Subcommittee

Vulnerability Management Metrics: Top 10 KPIs To Measure Success

A Cloud Security Architecture Workshop

High-Value Targets: A 2025 Toolkit for Executive Cyber Protection- Shared screen with speaker view

10 Tenets of CISO Success

