The need for cybersecurity data and metrics: empirically assessing cyberthreat
Brandon Valeriano
Journal of Cyber Policy, 2022, vol. 7, issue 2, 140-154
Abstract:
Without assessment metrics and data, the cybersecurity community maintains no ability to evaluate the success or scope of operations. Calls for the collection of cybersecurity indicators are empty without strategic guidance on what indicators to collect, for what purpose, and for what method of analysis. This paper reviews the purpose, function and need for cybersecurity data and metrics with an in-depth review of United States metrics guidance offered in the National Defense Authorisation Act (NDAA) and National Institute of Standards and Technology (NIST) publications on metrics. Mission assessment is critical to evaluate the efficacy of ongoing and future cybersecurity efforts; assessments require quantitative metrics that place concrete values on indicators rather than subjective judgments.
Date: 2022
References: Add references at CitEc
Citations:
Downloads: (external link)
http://hdl.handle.net/10.1080/23738871.2022.2111997 (text/html)
Access to full text is restricted to subscribers.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:taf:rcybxx:v:7:y:2022:i:2:p:140-154
Ordering information: This journal article can be ordered from
http://www.tandfonline.com/pricing/journal/rcyb20
DOI: 10.1080/23738871.2022.2111997
Access Statistics for this article
Journal of Cyber Policy is currently edited by Emily Taylor
More articles in Journal of Cyber Policy from Taylor & Francis Journals
Bibliographic data for series maintained by Chris Longhurst ().