All Stories
Metrics, Rothman and Gaming the System
As usual, the purposefully provocative, belligerently blogging Mike Rothman has gone and done it again — aimed his treacly firehose at security metrics, Most recently, he’s waded into...
In security, metrics, Nov 18, 2006Good Metrics
Note from Andrew Jaquith: this essay is adapted from Chapter 2: Defining Security Metrics of my forthcoming book, Security Metrics: Replacing Fear, Uncertainty and Doubt from Addison-...
In security, metrics, books, Oct 15, 2006SANS, Schadenfreude and the Mac
I’ve got to wonder about the what planet the SANS people live on these days. Apparently, in an effort to make their semi-annual Top 10 list of vulnerabilities appear “fair and balance...
In security, Windows, Mac, vendor-bashing, May 02, 2006Open Letter to SC Magazine
Sent from my YG account 25 April 2006:
In security, Windows, Mac, Apr 24, 2006Good Patch Management Metrics
Earlier today I stumbled across the NIST patch management pub; it was released in November 2005.
In security, metrics, Mar 03, 2006Charging for Guaranteed Spam: Better Than It Sounds?
Much ink has been spilled over the recent AOL and Yahoo announcements that they will charge marketers five cents per e-mail to guarantee delivery of their mail, thus bypassing their s...
In security, spam, Feb 12, 2006Blended Threats == Hemlock Smoothies
An open letter to all anti-virus software makers: February 2, 2006 Dear Antivirus Industry, Why are you so addicted to the term “blended threat”? It seems to mean something specia...
In security, humor, vendor-bashing, Feb 11, 2006The Vulnerability Supply Chain
Yankee Group research may not be as well-subscribed as say, Gartner’s, but I like to think that it compares favorably with it. Earlier this year I wrote a research note titled Fear an...
In security, metrics, Dec 07, 2005The Natives are Restless
Many readers know that my day job is as a security technology analyst for Yankee Group. Well, it’s about that time of year where we start to wind down our research calendar. One of th...
In security, Windows, research, Nov 29, 2005The Devil’s Information Security Dictionary
Just saw the very funny Devil’s InfoSec Dictionary on the CSO site. Of course, I had to add a few definitions of my own: Blended threat: a hemlock smoothie Process, Security Is A: a...
In security, humor, Nov 14, 2005Featured
-
SRE Metrics and Security Measurement
In metrics, -
Five Things the Last Decade Taught Me About Security Metrics
In metricon, -
The Twenty-Year War on Cybercrime
In security, risk, big data, -
Review of Stephen Few’s “Information Dashboard Design, Second Edition”
In visualization, -
Cybersecurity for Machine-to-Machine (M2M) Networks
In security, -
“Everything was green. Mulally thought that was odd for a company losing billions.”
In strategy, leadership, -
Escaping the Hamster Wheel of Pain
In security, hamsters, books,