Software Engineering Institute (SEI) Podcast Series · Members of Technical Staff at the Software Engineering Institute

Cybersecurity Metrics: Protecting Data and Understanding Threats

·27 min·1 clip
Bill uses the 2015 OPM breach to show why logs, access tracing, and two-factor matter.
1. Software Engineering Institute (SEI) Podcast Series episode "Cybersecurity Metrics: Protecting Data and Understanding Threats" centers on cybersecurity measurement at the SEI. 2. Suzanne Miller hosts Bill Nichols, a principal researcher who leads software engineering measurement and analysis, and he explains why that background matters. 3. The episode asks what cybersecurity measurement is for, and Bill answers that measurement should start with goals, decisions, and what needs to be protected. 4. Bill says cybersecurity is important because "everything we own is potentially vulnerable," including identities and connected systems. 5. He defines the main measurement target as protecting information, data, and access to a system. 6. Bill adds that cybersecurity metrics can examine threats, exposures, the value of assets, and the risks if information is damaged or exposed. 7. Suzanne asks how cybersecurity metrics differ from software engineering metrics, and Bill contrasts productivity and defect measures with security-specific compromise risks. 8. Bill names MITRE's common weaknesses enumeration and the vulnerability list as examples of security categorizations. 9. He says cybersecurity focuses on weaknesses that could expose data or compromise a system, rather than general software qualities like maintainability. 10. Bill describes major challenges as unclear scope, weak standardization, and data availability, especially when proprietary codebases are closely held. 11. He says security measurement is complicated by an active adversary, so the field is not stable and behaves like a "cat and mouse game." 12. Bill and Suzanne use the 2015 Office of Personnel Management incident to discuss public breach analysis and the difficulty of knowing who was behind the attack. 13. Bill says fine-grained logs helped trace access, privilege elevation, and likely exploit paths in that incident. 14. He points to two-factor authentication and robust access management as practical measurement-linked defenses. 15. Bill also recommends monitoring normal network profiles so outlier IPs from suspicious sources can stand out. 16. Suzanne and Bill connect this to attack-surface analysis, hardened access points, source code review, and forensic log analysis. 17. Bill stresses that measurement definitions matter, citing the ambiguity of "mean time to recovery" and the difference between "normal state" and "acceptable state." 18. The conversation has a practical interview style with back-and-forth clarification, examples, and repeated returns to context and definitions. 19. Listeners who work in cybersecurity, software assurance, or risk measurement will get the most value from this episode. 20. Listeners wanting a narrative story or a fast technical demo may skip it.
Listen to the show on