 |
| |
 |
|
|
|
|
SECURITY METRICS - RAVs (Risk
Assessment Values)
Security metrics
are the cornerstone of change control and information security
management. Factual security numbers, measures based on security and
loss control effectiveness as opposed to the number of implemented
security and loss controls.
The OSSTMM refers to security metrics as RAVs or Risk Assessment Values.
While not formulating risk assessments, the RAVs are the building block
of any risk assessment. It is the facts for which you make your relative
assumptions on. It is like the difference between knowing you need a
large desk and knowing that you need one which 2.2m x 3m.
There is no fancy algorithm and there are absolutely no extraneous
weights on the data. There are also no assumptions and no complex
comparisons. It's a pure metric. The RAVs are designed to be simple,
quickly calculated, accurate, and realistic. Furthermore, the RAVs are
designed to be equally accurate whether calculating the security and
loss controls measures for a military base, an office building, a bridge,
a Mars rover, a computer network, or a single, interactive application
on a computer.
RAVs are part of the OSSTMM and are protected under the Open Methodology
License. Use of the RAVs is open to all both privately and commercially.
|
TOOLS & SOFTWARE |
PRICE |
DESCRIPTION |
|
RAV Spreadsheet
(.xls
or
.ods) |
FREE |
The standard calculation
functions for Operational Security and Actual Security in a simple
spreadsheet. Suggested for experts only. |
|
RAV Formula |
FREE |
The standard
calculation formula for Operational Security and Actual Security.
Suggested for developers only. |
|
Security
Testing Audit Report (STAR) |
FREE |
The primary purpose of this
Audit Report is to provide a standard reporting scheme based on a
scientific methodology for the accurate characterization of
security through examination and correlation in a consistent and
reliable way. The secondary purpose is to provide guidelines which
when followed will allow the auditor to provide a certified OSSTMM
audit. |
The best use of RAVs is for measuring security in a consistent and
repeatable manner regardless of the company who provides testing. RAVs
also allow for a percentage which is comparable through industry,
organization size, region, policy, and financials. RAVs provide a
benchmark that allows for third parties such as insurance companies,
government auditors, industry regulators, and military personnel to
correctly classify an organizational group from a single unit up to a
national defense with one standard measurement.
|

|
ISECOM is an open, collaborative,
non-profit, scientific, security research organization registered in Catalunya, Spain. All research here has been performed without
commercial or partisan influence. Contact
us directly to be a security researcher on the ISECOM team.
 
|
|
Disclaimer:
While all documents on this site are available under
Copyleft and the
Open Methodology License,
do check the licenses within each tool or document prior to copying,
modifying, or distribution for any individually stated requirements.
Additionally, all research is provided here for information purposes
only and ISECOM is not responsible for any misuse. |
|
|
|