CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy

A security analyst is preparing a quarterly report for the Chief Information Security Officer (CISO) and other executive stakeholders. The report needs to convey the current state of the organization's security posture in a clear, concise, and business-focused manner. Which of the following types of metrics would be MOST appropriate for this audience?

  1. ALines of code scanned by static analysis tools
  2. BCPU utilization of SIEM servers
  3. CNumber of firewall rules created per week
  4. DPercentage reduction in critical vulnerabilities over time
Show answer & explanation

Correct answer: D. Percentage reduction in critical vulnerabilities over time

Executive stakeholders are primarily concerned with the overall risk posture and business impact. A percentage reduction in critical vulnerabilities directly demonstrates risk reduction and security improvement in terms that business leaders can understand and value.

Why the other options are wrong

  • A. This is a highly technical development metric, not suitable for executive reporting on overall security posture.
  • B. This is an infrastructure performance metric, not directly indicative of security posture for executives.
  • C. This is a technical operational metric irrelevant to executive risk posture.

Executive Security Metrics

High-level, business-oriented metrics designed to inform executive leadership about the organization's overall security posture, risk reduction, and the effectiveness of security investments.

  • Focus on risk, compliance, and business impact.
  • Avoid overly technical jargon.
  • Demonstrate progress and value of security initiatives.

Memory trick: Executives want to see the 'big picture' of protection and progress.

More Reporting and Communication questions