CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO) and other executive stakeholders. The report needs to convey the current state of the organization's security posture in a clear, concise, and business-focused manner. Which of the following types of metrics would be MOST appropriate for this audience?
- ALines of code scanned by static analysis tools
- BCPU utilization of SIEM servers
- CNumber of firewall rules created per week
- DPercentage reduction in critical vulnerabilities over time
Show answer & explanationAnswer & explanation
Correct answer: D. Percentage reduction in critical vulnerabilities over time
Executive stakeholders are primarily concerned with the overall risk posture and business impact. A percentage reduction in critical vulnerabilities directly demonstrates risk reduction and security improvement in terms that business leaders can understand and value.
Why the other options are wrong
- A. This is a highly technical development metric, not suitable for executive reporting on overall security posture.
- B. This is an infrastructure performance metric, not directly indicative of security posture for executives.
- C. This is a technical operational metric irrelevant to executive risk posture.
Executive Security Metrics
High-level, business-oriented metrics designed to inform executive leadership about the organization's overall security posture, risk reduction, and the effectiveness of security investments.
- Focus on risk, compliance, and business impact.
- Avoid overly technical jargon.
- Demonstrate progress and value of security initiatives.
Memory trick: Executives want to see the 'big picture' of protection and progress.