Metricon 1.0
The MetriCon 1.0 Agenda follows below with presentation materials from each author. A prose Digest of the meeting's conversation is here(info).

8:30-9:00 Keynote

  • Resolved: Metrics are nifty - Andrew Jaquith, Yankee Group HTML(info)
  • Resolved: Metrics are too hard - Steve Bellovin, Columbia University PDF(info) and TXT(info)

9:00-10:30 Software Security Metrics - Gunnar Peterson, track chair

  • A Metric for Evaluating Static Analysis Tools - Brian Chess & Katrina Tsipenyuk, Fortify Software PPT(info)
  • An Attack Surface Metric - Pratyusa Manadhata & Jeannette Wing, Carnegie-Mellon PPT(info)
  • "Good enough" Metrics - Jeremy Epstein, WebMethods PPT(info)
  • Software Security Patterns and Risk - Thomas Heyman & Christophe Huygens, U of Leuven PDF(info)
  • Code Metrics - Pravir Chandra, Secure Software PPT(info)

11-12:30 Enterprise & Case Studies A - Adam Shostack, track chair

  • Data Breaches: Measurement Efforts and Issues - Chris Walsh PDF(info)
  • The Human Side of Security Metrics - Dennis Opacki, Covestic PPT(info)
  • No Substitute for Ongoing Data, Quantification, Visualization, and Story-Telling - John Quarterman & Gretchen Phillips, InternetPerils PPT(info)
  • What are the Business Security Metrics? - Shawn Butler, MSB Associates PDF(info)

1:30-3:00 Enterprise & Case Studies B - Betsy Nichols, track chair PDF(info)

  • Leading Indicators in Information Security - John Nye, Symantec PDF(info)
  • Top Network Vulnerabilities Over Time - Vik Solem PDF(info)
  • IAM Metrics Case Study - Andrew Sudbury, ClearPoint Metrics PPT(info)
  • Assessment of IT Security in Networked Information Systems - Jonas Hallberg & Amund Hunstad, Swedish Defence Research Agency PDF(info)

3:30-5:00 Governance - Dan Geer, track chair

  • The only metrics that matter are for decision support - Dan Geer, Verdasys PPT(info)
  • Model Concepts for Consideration and Discussion - Bryan Ware, Digital Sandbox PPT(info)
  • Mission and Metrics from Different Views: Firm/Agency, Industry, and Profession - Kawika Daguio, Northeastern University PPT(info)
  • Measuring Information Security Risk - Bob Blakley, Burton Group PPT(info)
  • Information Assurance Metrics Taxonomy - Wayne Jansen, NIST PPT(info)

6:00 Dinner/Rump Session

  • The Industrial Security Incident Database - Eric Byres, Wurldtech Analytics & David Leversage, British Columbia Institute of Technology PDF(info)
  • Milk or Wine: Does Software Security Improve with Age? - Andy Ozment and Stuart Schechter, MIT Lincoln Laboratory PDF
  • Security Metrics - Pete Lindstrom, Spire Security PPT(info)