Security program metrics and monitoring
A metric is a measurement of a process to determine how well the process is performing. Security-related metrics indicate how well the controls are able to mitigate the risk. For example, the system uptime metric helps us to understand whether the system is available to the user as per the requirements. The following are some examples of security-related metrics:
- Percentage of critical server for which the penetration test is conducted
- Percentage of high-risk findings closed within a month
- Percentage of deviation from the information security policy
- Percentage of computers having unsupported operating systems
- Percentage of computers with updated patches
- Average response time to handle the incident
Objective of metrics
On the basis of effective metrics, an organization evaluates and measures the achievement and performance of various processes and controls. The main objective of a metric is to help management...