CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A cybersecurity analyst is preparing a quarterly report for the Chief Information Security Officer (CISO). The CISO has requested a metric that demonstrates the efficiency of the security team in addressing newly identified vulnerabilities. Which of the following Key Performance Indicators (KPIs) would BEST address the CISO's request?
- ANumber of critical vulnerabilities identified
- BPercentage of assets scanned monthly
- CTotal number of security incidents reported
- DAverage time to patch critical vulnerabilities
Show answer & explanationAnswer & explanation
Correct answer: D. Average time to patch critical vulnerabilities
Average time to patch critical vulnerabilities directly measures the efficiency of the security team in remediating critical issues, which is precisely what the CISO requested to assess efficiency in addressing newly identified vulnerabilities.
Why the other options are wrong
- A. This metric indicates discovery, not the efficiency of addressing them.
- B. This shows scan coverage, not the team's efficiency in fixing vulnerabilities.
- C. This measures incident volume, not vulnerability remediation efficiency.
Vulnerability Remediation Efficiency KPI
A metric used to assess how quickly and effectively security teams address and resolve identified vulnerabilities, often focusing on critical or high-severity issues.
- Measures the speed of patching or fixing vulnerabilities.
- Often tracked for different severity levels (e.g., critical, high).
- Helps demonstrate the responsiveness of the security team.
Memory trick: Speedy patches protect the kingdom.