CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A cybersecurity analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The report needs to summarize the organization's adherence to the ISO 27001 framework, specifically focusing on the progress made in implementing controls for information security incident management. Which of the following metrics would be MOST relevant to include in this report?

  1. ATotal number of vulnerabilities identified in external penetration tests.
  2. BNumber of successful phishing attempts blocked by email filters.
  3. CPercentage of security incidents resolved within the target Mean Time To Resolution (MTTR).
  4. DAverage time taken to provision new user accounts in critical systems.
Show answer & explanation

Correct answer: C. Percentage of security incidents resolved within the target Mean Time To Resolution (MTTR).

The question specifically asks about adherence to ISO 27001 information security incident management controls. MTTR (Mean Time To Resolution) is a direct measure of incident response effectiveness and therefore highly relevant. The percentage of incidents resolved within the target MTTR indicates performance against established service level agreements or internal targets.

Why the other options are wrong

  • A. This relates to vulnerability management and testing, which is distinct from incident resolution performance.
  • B. While a security metric, this relates to preventative controls (phishing protection) rather than incident management resolution.
  • D. This metric concerns identity and access management, not information security incident management.

ISO 27001 Incident Management Metrics

Metrics used to measure an organization's performance in handling information security incidents according to ISO 27001 guidelines.

  • Focus on incident detection, response, and resolution.
  • Examples include MTTR, incident backlog, and incident recurrence rates.
  • Helps demonstrate compliance and continuous improvement.

Memory trick: ISO 27001 is about managing incidents, so measure how fast you RESOLVE them.

More Reporting and Communication questions