CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst is preparing a quarterly report for the board of directors. The report needs to provide a high-level overview of the organization's cybersecurity posture and key risks. Which type of metric should the analyst primarily focus on to ensure the information is relevant and actionable for this audience?
- AOperational metrics, such as CPU utilization of SIEM servers.
- BStrategic metrics, such as risk exposure in financial terms or compliance adherence.
- CTechnical metrics, such as the total number of detected malware samples.
- DTactical metrics, such as the average time to analyze a security alert.
Show answer & explanationAnswer & explanation
Correct answer: B. Strategic metrics, such as risk exposure in financial terms or compliance adherence.
For a board of directors, strategic metrics that translate cybersecurity risks into business terms (financial impact, compliance, brand reputation) are most relevant and actionable, as they align with overarching business objectives and governance.
Why the other options are wrong
- A. Operational metrics are too granular and technical for a board-level report.
- C. Technical metrics like malware counts are not directly actionable or easily understood in a business context by the board.
- D. Tactical metrics are too focused on day-to-day security operations and lack the strategic perspective required by a board.
Strategic Cybersecurity Metrics
Key Performance Indicators (KPIs) that measure the overall effectiveness of a cybersecurity program in meeting organizational objectives, typically presented to executive leadership and boards.
- Focus on business impact, risk posture, and compliance.
- Often expressed in financial terms, percentages of compliance, or high-level risk ratings.
- Used for governance, investment decisions, and long-term planning.
Memory trick: The Board cares about 'Strategy, Success, and Spending'.