Creating a Security Metrics Program: How to Measure Success - SANS ICS Security Summit 2019
Presenter: Jason Christopher, CTO, Axio Global, Inc. We’ve heard it all before: “Our team handles 500,000 cyber-attacks a day.” “Cyber threats are increasing.” “We track cybersecurity as a critical risk for our organization.” But what does any of that really mean? Creating measurements and metrics around cybersecurity is difficult, but so is building a sustainable metrics program, regardless of the subject matter. Early tasks, including measuring what is important and resource management, can be undermined by external pressures to tell a certain narrative or prove certain results. How can our industry create unbiased, yet compelling, metrics? What is the right-sized team or amount of resources for a metrics program? Is such a program sustainable? This presentation will cover not only the basics of cybersecurity metrics, but also lay the foundation for how s security team can create a new metrics program that goes beyond red/yellow/green or compliance. By moving to objective and repeatable metrics, utility security leaders will be able to not only justify programmatic improvements, but also track trends across environments and future projects. With research from the U.S. Department of Energy, the Electric Power Research Institute, and the National Institute of Standards and Technology, practitioners can build a defensible security metrics program across strategic, tactical, and operational levels of the utility. SANS Summit schedule: http://www.sans.org/u/DuS The annual ICS Security Summit brings together practitioners and leading experts to share ideas, methods, and techniques for defending control system environments. In-depth presentations and interactive panel discussions deliver real-world approaches that work and make a difference for the individuals fighting this fight every day.

Cybersecurity Metrics

Stop Wasting Money on SANS GIAC Certificates (Here's Why)

Preventing Your Physical Access Control System from Being Used Against You - SANS ICS Summit 2019

The Cycle of Cyber Threat Intelligence

SANS ICS HyperEncabulator

Zero-Trust Networks: The Future Is Here - SANS Blue Team Summit 2019

A case study master class on Reporting Cyber Risk to the Board by Omar Khwaja

The First 6 Months as a CISO Determines Success or Failure

Build it Once, Build it Right: Architecting for Detection - SANS Tactical Detection Summit 2018

Cybersecurity Metrics

A 28-year-old Steve Jobs gives a talk at the 1983 International Design Conference in Aspen

How To Manage Security Risks & Threats | Google Cybersecurity Certificate

How to Get Promoted: Developing Metrics to Show How Threat Intel Works - SANS CTI Summit 2019

Reflections of a New CISO: 5 Lessons Learned | SANS@MIC Talk

Practical Solutions to Supply Chain Attacks - SANS ICS Security Summit 2019

Why The Russian Accent Terrifies Everyone

Threat Hunting via Sysmon - SANS Blue Team Summit

A Cloud Security Architecture Workshop

Ronny Chieng Address | Harvard Class Day 2026

