The Security Data and Survey Directory
Security data. Everybody needs it. Lots of companies and organizations are producing it. Here's where to find it.
Mon, November 29, 2010
CSO — Survey statistics and research studies are a great way to help you recognize impending threats and emerging attack vectors. Data can even help you identify and substantiate the need for specific budgetary increases to the C-suite. So we've compiled this semi-exhaustive list (it certainly made us tired, anyway) of where to find research-backed data you can use.
Where possible we've made note of some key facts about each survey to help you decide its potential value: the number and type of respondents, who sponsored the survey (if a security product or service vendor was involved, which could influence the perception of bias), and whether the report requires registration or a fee.
This list will be updated and expanded on CSOonline.com. Have suggestions about additional data sources? Email CSO editor Derek Slater at dslater@cxo.com. Data sources will be added, removed or modified at the whim of the editor. (We like to be inclusive but make no promises.) Many thanks to Shawna McAlearney for compiling the bulk of the initial directory.
Last update: 11/29/10. Additions planned ASAP: Click fraud, brand abuse, GRC, software security
Research Survey & Study Categories (click to skip directly to any category)
* Security Spending, Budgets & Priorities
* Physical Security and Loss Prevention
* Business Continuity & Disaster Recovery
* Security Careers, Skills, Salary and Benefits
* Virtualization & Cloud Computing
Risk Management and Security Leadership
State of the CSO 2010: Progress and Peril
Conducted by: CSO
Number of respondents:
Today, as organizations come to grips with a wide swath of risks, the 2010 State of the CSO survey shows those organizations are rapidly adopting a more sophisticated view of security. Of course, there's more work to be done--most prominently in the areas of security metrics and awareness programs.
In-depth reading on risk management
* Turning ERM strategy into specific systems projects
* The CISO's new focus: IT risk
Global Risk Management Survey, Sixth Edition: Risk Management in the Spotlight
Conducted by: Deloitte
Sponsored by: Unsponsored
Number of respondents: Responses from 111 financial institutions worldwide with more than $19 trillion in total assets.
2009 survey looks at risk management during economic downturn and finds more than half of firms falling under Basel II requirements reported they were nearly in compliance or had already complied. Also, only 24 percent have a defined and approved enterprise-level statement of the firms risk appetite; 72 percent of firms with ERM programs reported that the quantifiable benefits exceeded its costs.


