CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The report needs to highlight the organization's adherence to regulatory requirements and its overall security posture in relation to industry benchmarks. Which of the following metrics would be MOST appropriate to include?
- ATotal number of vulnerabilities identified.
- BPercentage of systems compliant with security baselines.
- CNumber of successful phishing attempts.
- DMean Time To Detect (MTTD) incidents.
Show answer & explanationAnswer & explanation
Correct answer: B. Percentage of systems compliant with security baselines.
Compliance with security baselines directly addresses adherence to regulatory requirements and security posture against established standards, making it highly relevant for a CISO's report on overall security and compliance.
Why the other options are wrong
- A. This metric shows vulnerability discovery, but not necessarily the organization's compliance or its posture against industry benchmarks without context of remediation or severity.
- C. While important, this is an operational metric that doesn't directly address regulatory compliance or overall security posture against industry benchmarks.
- D. MTTD is an operational efficiency metric for incident response, not a direct indicator of regulatory compliance or overall security posture against benchmarks.
Compliance Metrics
Quantitative measures used to assess an organization's adherence to internal policies, industry standards, and regulatory requirements.
- Demonstrate accountability to stakeholders.
- Help identify gaps in security controls.
- Often required for audits and certifications.
Memory trick: CISO's report needs compliance, not just incidents.