Lab Home | Phone | Search | ||||||||
|
||||||||
It is common to see statements such as the following which come from https://www.dhs.gov/science-and-technology/csd-elsmu. Defining effective information security metrics has proven difficult, even though there is general agreement that such metrics could allow measurement of progress in security measures and, at a minimum, rough comparisons of security between systems. . . . However, general community agreement on meaningful metrics has been hard to achieve. This is due in part to the rapid evolution of IT, as well as the shifting focus of adversarial action. This page neglects to state the real reason that agreement on meaningful metrics has been hard to achieve: it is not possible to construct a reasonable metric. This paper, which is based on results that have been known for a long time will demonstrate that under reasonable requirements for a metric, it is not possible to construct a metric. Hence, searching for such a metric is like searching for a pot of gold at the end of the rainbow. Host: Daniel Tauritz |