Resources for Measuring Cybersecurity

Paul Rosenzweig
Thursday, October 31, 2019, 3:01 PM

Announcing an annotated partial bibliography of publicly available cybersecurity measurement methodologies.

For those who are following along in my ongoing quest to develop concrete cybersecurity metrics, I want to point you to a new, valuable resource. My R Street colleague, Kathryn Waldron, has spent the last several months creating an annotated partial bibliography of publicly available cybersecurity measurement methodologies. The result is "Resources for Measuring Cybersecurity," a compendium of several dozen of the most prominent publications on the methodology of cybersecurity measurement. As she puts it: "Without accurate, standardized methods to measure cybersecurity, detecting and deterring cyber threats will continue to be more art than science. This partial attempt [to create a bibliography] will shed light on some of the most pervasive and exciting work that has been and is currently being done." I commend her work to your attention.


Paul Rosenzweig is the founder of Red Branch Consulting PLLC, a homeland security consulting company. He formerly served as deputy assistant secretary for policy in the Department of Homeland Security. He is a professorial lecturer in law at George Washington University, a senior fellow in the Tech, Law & Security program at American University, and a board member of the Journal of National Security Law and Policy.
}

Subscribe to Lawfare