CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO has requested a metric that illustrates the organization's effectiveness in reducing its overall attack surface over time. Which of the following would be the MOST appropriate Key Performance Indicator (KPI) to include?

  1. AAverage time to respond to a critical alert.
  2. BNumber of security incidents detected per month.
  3. CTotal number of security awareness training completions.
  4. DPercentage reduction in open high-severity vulnerabilities.
Show answer & explanation

Correct answer: D. Percentage reduction in open high-severity vulnerabilities.

Reducing the attack surface directly correlates with mitigating vulnerabilities. Therefore, the 'percentage reduction in open high-severity vulnerabilities' is the most direct and effective KPI to demonstrate the organization's success in shrinking its potential exposure to attacks over time.

Why the other options are wrong

  • A. This metric measures incident response efficiency, not the attack surface reduction.
  • B. This metric reflects detection capabilities, not the proactive reduction of the attack surface.
  • C. This metric relates to human factors and training, not the technical attack surface reduction.

Attack Surface Reduction KPI

An Attack Surface Reduction KPI measures the organization's success in minimizing the entry points and potential vulnerabilities that an attacker could exploit. It often focuses on vulnerability remediation and asset hardening.

  • Directly reflects proactive security posture improvement.
  • Often involves vulnerability management metrics.
  • Aims to reduce the likelihood of successful attacks.

Memory trick: Reduce the attack surface by patching the holes and shrinking the target.

More Reporting and Communication questions