Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium

A security team is evaluating the effectiveness of its incident response process. They collect data on the Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for various types of incidents over the past year. This data is then presented to management to show trends and identify areas for improvement. Which security concept is this activity primarily focused on?

  1. ASecurity frameworks
  2. BSecurity metrics
  3. CSecurity policies
  4. DSecurity laws and regulations
Show answer & explanation

Correct answer: B. Security metrics

Collecting and reporting on MTTD and MTTR are classic examples of using 'security metrics' to measure and evaluate the performance and effectiveness of security operations and processes.

Why the other options are wrong

  • A. Security frameworks provide a structure for managing security, not specific performance measurements.
  • C. Security policies define rules, not measure performance.
  • D. Security laws and regulations set compliance requirements, not performance indicators.

Security Metrics

Quantifiable measurements used to assess the effectiveness, efficiency, and impact of an organization's information security program and controls.

  • Help track progress, identify trends, and justify security investments.
  • Should be relevant, measurable, actionable, and timely.
  • Examples include patching compliance rate, number of incidents, time to detect/respond.

Memory trick: Metrics make security progress visible and actionable.

More Security Concepts questions