5 comments on “The Metrics

  1. Here is a link to that webinar recording

    Metrics are Bunk!?: The Zombie Apocalypse, Baseball, and Security Metrics

    https://365.rsaconference.com/community/connect/blog/2011/10/27/webcast-metrics-are-bunk-the-zombie-apocalypse-baseball-and-security-metrics

    Now that I read this post, I realize we didn’t even come close to answering the intent of your text based question.

    P.S. I’ve asked the securitymetrics list about MRIs during security questions.

    • Hi Joshua
      First of all, let me say again that the presentation you and Alex gave was truly awesome, and if someone didn’t see it yet it’s a must.

      Just to explain how scary Alex Pentlands’ work is, I’ve updated the blog with a link to Alex Pentland’s latest presentation on the subject of Influence Networks. It’s a video of a presentation he gave on the 9th of November, and in it he talks about his latest research.

      Around the 43th minute he makes the following statement, which to me was the most mind blowing human metrics I’ve ever heard:

      It turns out we can do even better than this. Since then what we’re done is we put the two things together – the fact that we can predict when you’re likely to buy, and that we can recruit – we can plan plot things that cause recruitment – and you can actually write down equations, which gives you analytic modules for ad campaigns and behavioral campaigns. That’s the first time you’ve ever heard that, ok? People always say “If you’ll spend that money we will give you that much yield” but we can actually tell you with 95% confidence, and we done this on stock purchases and app downloads, so believe that it’s real. Pretty interesting – and scary because it also work for political views.

      This why I asked about the question about monitoring people – because from the look of it, we’re heading fast to a very monitored future. What do you think?

      Thanks for the reply
      Uri

  2. Hey. As I tweeted, I liked your post, but cringed (violently) at the sight of that pie chart. Given what it was trying to communicate, I would think just an ordered list (with some magnitude description) would have been a better approach. Charts like that help foster the image of our profession being slightly more advanced than cavemen drawings and traveling dowsers.

    • Hi
      First of all, let me say that when I saw the pie chart for the first time I also sounded like Barbara Walters when Herman Cain told her that he wants to be Secretary of Defense. (WHAT?????)

      But than I thought to myself – isn’t it a great way to show how bad the current metrics are?

      So wonderful of you for getting it :)

      Cheers
      Uri

    • Hi Bob again
      I was thinking that maybe I should have given the translation of the chart (as I understand it), to show how funny it is.

      61.2% of the organizations think that their awareness program was successful by looking at the percentage of users who completed their information security awareness training (probably defining a % of the user population that is considered to be OK).
      12.2% of the organizations think that their awareness program was successful because when they look at current vs. past number of security incidents caused by user errors they see a reduction.
      06.1% of the organizations think that their awareness program was successful because when they surveyed users that completed awareness training it seems they understand information security better
      04.1% of the organizations think that their awareness program was successful because the percentage of users who successfully completed at least one information security awareness session seems to them as a good figure.
      02.0% of the organizations think that their awareness program was successful because when they checked it by actively targeting users and see if they responded responsibly (was it every user? a sample? we don’t know…)
      14.3% of the organizations think that their awareness program was successful because when they … We don’t really know. I’m also certain those organizations also don’t know as well…

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s