Securosis, Microsoft team up to solicit input for building a metrics model that measures efficiency and costs of security patching. Security consulting firm Securosis is spearheading a new effort to create metrics to quantify the cost and efficiency of an organization's security patching process. . Rich Mogull, founder of Securosis, says to date there's no real way to accurately measure the cost and productivity of an organization's security patch management process. "Those fully quantified [IT] risk models don't apply and the numbers aren't accurate," he says. "It's also bothered me to see those uber-metrics approaches that get an overview of everything in the security program. So why not start with one thing we can accurately measure and use it as a core for building security metrics?" Securosis, with the financial backing of Microsoft for the initial phase of the project, will gather input in an open submission process for the so-called Project Quant metrics model. Version 1 is planned for release by the end of June. The link at DarkReading is no longer available. . Uncover an innovative project aimed at evaluating expense and effectiveness in security update handling through a collaboration between Securosis and Microsoft.. Patch Management, Security Metrics, Cost Efficiency, Securosis Initiative. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.