Tolerable security metrics

Like most pursuits in life, computer security does not have good measures of success. This annoys everyone involved.

Dino Dai Zovi said it well:

Good security is hard and the feedback loop on decisions is long and the signal is low fidelity. It's not clear how many incidents were prevented or mitigated from which foundational decisions years prior.

To me, the ideal overall metric would be something like:

% probability of the company or its users being hacked

Or maybe:

% probability of the company’s top five most damaging risk scenarios happening

Unfortunately, that is not achievable in any honest or useful way.

So here is a brainstorm of security metrics that have at least some value:

A good metric is a great thing. It lets you know if you are moving in the right direction.

Ultimately, metrics are consumed by people: our coworkers. So beyond being clear, they should ideally be motivating. The best case is that a metric gives you the freedom to throw some spaghetti projects at the wall and maybe move it with a novel project.