At 7:48 PM +0530 7/18/06, stanley perreira wrote:
> Hello,
>
> I am trying to develop metrics for the ISO 27001. There doesnot seem
> to be much of consensus on how to go about it ?
>
> What are we supposed to measure here - is it the effectiveness of the
> controls or how many controls are being followed ?
If you cannot show your use of the control is effective, they you cannot
really be said to be following it.
--
Larry Kilgallen
> Hello,
>
> I am trying to develop metrics for the ISO 27001. There doesnot seem
> to be much of consensus on how to go about it ?
>
> What are we supposed to measure here - is it the effectiveness of the
> controls or how many controls are being followed ?
If you cannot show your use of the control is effective, they you cannot
really be said to be following it.
--
Larry Kilgallen
[ reply ]