摘要: |
In this presentation I will provide an overview of the meaning and purpose of measurement andhow to measurement can apply to cybersecurity. Measurement has a scientific definition and anengineering implementation but is used primarily to make economic decisions. Nonetheless,problems in measurement result from several causes include the following: a poorly definedconcepts, ill-defined objectives, lack of context, failure to connect the measures to outcomes,inattention to the quality aspect of the measure. These are especially problematic in cybersecuritybecause the relationship between measurements and outcomes can change for unexpectedreasons. Many of these problems can be addressed using structured frameworks that recognizethese sometimes-competing aspects of measurement. Some examples of measurements derivedusing disciplined frameworks will demonstrate how science supports engineering and bothsupport economic decisions. The emphasis will be on metrics for making economic decisions. Thispresentation will conclude by noting that some emerging trends in software engineering such asincreased reliance upon automated tools, use of “big data”, cloud computing, and end-to-enddigital engineering models will profoundly influence future measurement. Each of these bringsnew challenges, but also promises more rigorous definition and documentation. |