what are external and internal security audits
Leveraging Security Metrics To Protect Your Network
Maybe we should just give up trying to maintain secure enterprise networks; its just too hard.
When we surveyed practitioners, 71% of respondents admitted that their networks are exposed to external threats due to misconfiguration issues in their security device infrastructure. Verizon reports that 79% of organizations fail to maintain PCI compliance from their prior years assessment. More than 50 percent told us they had no idea how many of their organizations internal hosts were exposed to the Internet.
We know that even in this era of constrained budgets, enterprises are spending more on network securityand yet 75% of network and security pros agree that the advantage is still on the side of the attacker. Verizon reposts that security erosion over the course of the year between PCI audits is the norm with most enterprises, despite the fact that we know theres a correlation between slippage and data breaches.
Maybe its time to re-evaluate our priorities. As our CTO Dr. Mike points out, theres a general consensus to focus on the core controls. If youre already covering 90% of the basics, security pros agree its more wise to push for 100% versus expand the number of controls.
But if youre focused on the core controls, how do you know what percentage level youre at, and where the areas of exposure are? Thats where security metrics come in.
!doctype>