Skip to main content

Security Metrics

  • Chapter
  • First Online:
IT Security Controls
  • 2365 Accesses

Abstract

It has always been a struggle for information security professionals to measure “the effectiveness” of IT security controls. In the 1980s, “orange books” were released for security professionals as a standard to set basic requirements for assessing the effectiveness of security controls built into a computer system (Figure 7-1), which was a part of the Rainbow Series published by the US National Computer Security Center. The most well-known orange book is the Trusted Computer System Evaluation Criteria (TCSEC) and its European counterpart, Information Technology Security Evaluation Criteria (ITSEC). The Common Criteria for Information Technology Security Evaluation (in short, ISO/IEC 15408) replaced those books. It created a framework for defining security levels for systems (hardware, software, or firmware) and determining acceptable testing methods and certifying system compliance to defined assurance levels.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+
from €37.37 /Month
  • Starting from 10 chapters or articles per month
  • Access and download chapters and articles from more than 300k books and 2,500 journals
  • Cancel anytime
View plans

Buy Now

eBook
EUR 17.99
Price includes VAT (Netherlands)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
EUR 70.84
Price includes VAT (Netherlands)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

Notes

  1. 1.

    www.iso.org/standard/50341.html

  2. 2.

    www.csoonline.com/article/3432138/how-much-should-you-spend-on-security.html

  3. 3.

    Kaspersky IT Security Economics 2020_Executive Summary.pdf

Author information

Authors and Affiliations

Authors

Rights and permissions

Reprints and permissions

Copyright information

© 2022 The Author(s), under exclusive license to APress Media, LLC, part of Springer Nature

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Viegas, V., Kuyucu, O. (2022). Security Metrics. In: IT Security Controls. Apress, Berkeley, CA. https://doi.org/10.1007/978-1-4842-7799-7_7

Download citation

Publish with us

Policies and ethics