I am writing a book on security metrics for Addison-Wesley Publishing and Symantec Press. The book, appropriately titled Security Metrics, is expected to be available in 2006.
To give folks an opportunity to see what I'm up to, I've posted portions of the manuscript online:
Since this is a wiki, if you are a member of the securitymetrics.org website you can add comments directly onto the posting pages. In fact, I'd love it if you did.
--Andrew