A thorough overview of the computer security industry offers an objective study of threats to companies and how they can change to confront them effectively, outlining specific and emergent threats, the tools used to assess them, how the security industry needs to evolve to meet security problems, how companies can evaluate their own security programs, future trends, and the issues of liability, user education, and more. (All Users)
Thinking about the metrics around InfoSec is a vital and mostly unsolved problem for this reasonably young scientific field. I highly recommend this book for people doing business in the InfoSec field.