Getting the time dimension right
If you are developing or using security metrics, it’s inevitable that you’ll have to deal with the dimension of time. It’s harder than it looks and I’ve seen many people make mistakes with it, and in doing so, rendering their overall metrics faulty or worse. The problems often start with our basic concepts and how we use words.
Morgan and Henrion (1990) offer excellent "ten golden rules" in relation to quantitative risk and policy analysis.
Accurate, timely information is fundamentally important to every organization. Decisions about how to allocate resources to ensure its confidentiality, integrity, and availability are among the most significant ones that an organization can make.