Information Security Program Metrics
A metric is the measurement of a process used to determine how well it is performing. Security-related metrics indicate how well controls are able to mitigate risks. For example, a system uptime metric indicates whether the system is available to users as per the requirements. The following are some examples of security-related metrics:
- Percentage of critical servers for which penetration testing has been conducted
- Percentage of high-risk findings closed within a month
- Percentage of deviation from the information security policy
- Percentage of computers having unsupported operating systems
- Percentage of computers with updated patches
- Average response time to handle incidents
Objective of Metrics
By using effective metrics, organizations evaluate and measure the achievement and performance of various processes and controls. The main objective of a metric is to help management in decision-making and to facilitate...