Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is presenting the annual information security program report to the executive committee. The committee expresses concern that despite significant investment in security technologies, the reported security incidents, though contained, have not decreased in frequency. They question the return on investment (ROI) of the security program. Which of the following metrics would BEST demonstrate the value and effectiveness of the security program beyond incident counts?
- AMean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for incidents.
- BPercentage of systems patched within the service level agreement (SLA).
- CNumber of security awareness training sessions conducted.
- DTotal number of vulnerabilities identified and remediated.
Show answer & explanationAnswer & explanation
Correct answer: A. Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for incidents.
The executive committee is concerned about ROI and the program's effectiveness despite incidents not decreasing. While incident frequency is a raw count, demonstrating improved MTTD and MTTR shows that the program is effectively containing and minimizing the impact of incidents, thereby reducing overall business risk and demonstrating value, even if prevention isn't 100% successful.
Why the other options are wrong
- B. Patching compliance is a good operational metric but doesn't directly address the executive's concern about the value of the overall program in managing incidents.
- C. Number of training sessions indicates activity, not necessarily the effectiveness or value of the security program in reducing risk.
- D. Vulnerability remediation shows proactive effort but doesn't quantify the program's ability to handle actual incidents or its value to the business when incidents occur.
Value-Driven Security Metrics
Metrics that quantify the business impact and effectiveness of the information security program, often expressed in terms of risk reduction, resilience, or cost savings, rather than just technical counts.
- Translates security performance into business terms.
- Demonstrates ROI and program effectiveness to executives.
- Focuses on impact, not just activity (e.g., MTTD, MTTR, risk reduction).
Memory trick: Show the Speed, Show the Save, Not Just the Scans.