CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO wants to understand the organization's adherence to security policies and compliance frameworks. Which of the following KPIs would BEST demonstrate compliance with established security policies?

  1. ANumber of vulnerabilities categorized as 'critical'
  2. BNumber of security awareness training sessions conducted
  3. CPercentage of systems with an up-to-date asset inventory
  4. DMean Time To Respond (MTTR) to security incidents
Show answer & explanation

Correct answer: C. Percentage of systems with an up-to-date asset inventory

Many security policies and compliance frameworks (like NIST, ISO 27001) mandate accurate and up-to-date asset inventories. A high percentage of systems with an up-to-date asset inventory directly demonstrates adherence to this fundamental policy requirement.

Why the other options are wrong

  • A. This measures vulnerability posture, not policy adherence directly.
  • B. This measures training activity, not directly the enforcement or adherence to security policies across systems.
  • D. This measures incident response efficiency, not adherence to security policies.

Compliance Reporting Metric (Policy Adherence)

A quantifiable measure used to demonstrate an organization's adherence to internal security policies and external compliance frameworks, often focusing on foundational controls and documentation.

  • Verifies implementation of mandated controls.
  • Often relates to asset management, configuration management, or access control policies.
  • Shows proactive effort in maintaining a secure state.

Memory trick: Adherence means 'policies are followed' and 'assets are known'.

More Reporting and Communication questions