I was listening to the Cyber Risk Management Podcast and the topic of discussion was cybersecurity product efficacy. Check it out on your next lunch break. They referenced a report released by Debate Security called Cybersecurity Technology Efficacy: Is cybersecurity the new "market for lemons"?
The report has a little of something for everyone but my key takeaway was a standard way to define efficacy for products. One of the ways discussed in the podcast was, as a vendor, to have your products evaluated by a third party like MITRE's ATT&CK Evaluations. Further thoughts on the matter? Agree or disagree with anything in the report?
Efficacy - defined by four characteristics:
Capability - When properly installed and configured, how well does the solution deliver its stated security mission? Is it fit for purpose?
Practicality - How easy is it for organizations to implement, integrate, operate and maintain? Is it fit for use?
Quality - How well designed and built is the solution to avoid vulnerabilities and negative impact?
Provenance - How much security risk is there in the vendor and it’s supply chain, based on how they work and who they are?