ABSTRACT

Managing information security will typically require a variety of decisions including those involving strategy and management as well as those in administration and operational areas. Clearly, the information or feedback needed will be very different for making prudent decisions in the various areas and, consequently, the metrics needed will be quite different.