Monitor the security of information
Security monitoring requires:
- A structured framework for the definition of annual objectives and steps of the action plans
- Indicators allowing to compare the results to the objectives:
- Quantitatively and qualitatively,
- Relatively to assigned delays.
- Inputs form external sources allowing to benchmark the organization
What MEHARI provides in this domain:
- A flexible framework, consistent to different processes and management styles for security, because:
- Organizations may decide to change their way to monitor security
- The requirements of management may follow the maturity level reached by the organization
- Several synthetic reports and measurements
- Risk and vulnerability levels
- Security themes (16 criteria such as access control, continuity planning, ...)
- Compliance measurement to all ISO 17799:2005 controls
- Dashboard of critical risks