Quantitatively Differentiating System Security

  • Stuart Schechter

The First Workshop on the Economics of Information Security |

Security is not considered a priority by developers of shrink-wrap systems because without a means to accurately and understandably measure it, security fails to provide a competitive advantage. I assert that the cost to break into a system is an effective metric, that this metric can be measured from the start of testing until product retirement, and that using this metric to differentiate products will provide developers with the competitive advantage needed to lead the industry to more secure systems.