CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security team is preparing for a compliance audit against PCI DSS. They need to demonstrate that all systems processing cardholder data are regularly scanned for vulnerabilities and that critical findings are remediated promptly. Which of the following KPIs would be MOST suitable to include in their compliance report to satisfy this requirement?

  1. AAverage time to remediate critical vulnerabilities (MTTR-V).
  2. BNumber of security awareness training completions per quarter.
  3. CPercentage of phishing emails successfully blocked at the gateway.
  4. DTotal number of firewall rules in place.
Show answer & explanation

Correct answer: A. Average time to remediate critical vulnerabilities (MTTR-V).

PCI DSS requires prompt remediation of vulnerabilities. The Average Time to Remediate Critical Vulnerabilities (MTTR-V) directly measures how effectively and quickly the organization addresses these findings, which is a key compliance metric.

Why the other options are wrong

  • B. While important for compliance, security awareness training is not a direct measure of vulnerability scanning and remediation effectiveness.
  • C. Phishing email blocking is a perimeter defense metric, not directly related to internal system vulnerability remediation.
  • D. The total number of firewall rules doesn't indicate the effectiveness of vulnerability management or remediation speed.

Mean Time To Remediate Vulnerability (MTTR-V)

The average time an organization takes to fix or mitigate a discovered security vulnerability from its identification to full resolution.

  • Measures the efficiency of the vulnerability management program.
  • Lower MTTR-V indicates a more agile and effective remediation process.
  • Often a key metric for compliance frameworks like PCI DSS.

Memory trick: PCI cares about 'Vulnerabilities Fixed, Fast'.

More Reporting and Communication questions