GOV-023 Security Measures Performance Measurement
Description
A security metrics report is produced at a defined cadence covering at minimum security training completion, vulnerability remediation against its defined service level, security incident rate and audit finding closure. Each metric carries a defined target and its current value against that target, with the trend across prior periods. The report names the executive or committee it is delivered to and records their acknowledgement.
Rationale
A programme with no measured outcome cannot show improvement or argue for resource. The metrics are also the numbers an external assurance report quotes. The four named metrics are the floor because each has an owning control that already produces the number: HRS-004 for training completion, INF-007 for vulnerability remediation, INC-001 for incidents and GOV-011 for audit findings. Application-level security metrics and privacy accountability reporting are not required here.
Applicability (9 profiles)
Framework Mappings (18)
| AIS-03 | Application Security Metrics | partial |
| DCS-17 | Datacenter Metrics | informative |
| GRC-02 | Risk Management Program | informative |
| TVM-12 | Vulnerability Management Metrics | informative |
| AIS-03 | Application Security Metrics | partial |
| DCS-17 | Datacenter Metrics | informative |
| GRC-02 | Risk Management Program | informative |
| TVM-12 | Vulnerability Management Metrics | informative |
| NIS2-Art.21.2.f | Assessment of the Effectiveness of Risk-Management Measures | informative |
| NIS2-CIR-1.1 | Policy on the Security of Network and Information Systems | informative |
| NIS2-CIR-2.2 | Compliance Monitoring | informative |
| NIS2-CIR-7 | Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measures | informative |
| AT-6 | Training Feedback | informative |
| PM-27 | Privacy Reporting | partial |
| PM-6 | Measures of Performance | full |
| MS-2.7-004 | AI System Security and Resilience Evaluation | MS-2.7-004 | full |
| CC2.1 | COSO Principle 13: Uses Relevant Information | partial |
| CC4.1 | COSO Principle 16: Conducts Ongoing or Separate Evaluations | informative |
Evidence (2)
Security metrics report showing defined KPIs covering control effectiveness, risk posture, training completion, and incident rates, reported to management.
Example: Monthly or quarterly security metrics report (Confluence / GRC dashboard export / PDF), showing: metric name, target, current value, trend, and reporting period, distributed to named management recipients.
Test: Request the last two security metrics reports. Verify: (1) reports are produced within the defined cadence, (2) metrics cover at minimum: training completion rate, open vulnerability count or SLA compliance, incident rate, and audit finding closure rate, (3) current values are compared to targets, (4) the report is addressed to or acknowledged by a named executive or security committee.
Evidence that metrics results have been acted on: meeting minutes or action log showing management reviewed metrics and assigned follow-up items.
Example: Security committee or management meeting minutes (Google Drive), referencing the metrics report, showing: the date of review, attendee list including named management, and any action items generated from metric results.
Test: Request meeting minutes from the most recent security metrics review. Verify: (1) metrics were discussed, (2) at least one management-level attendee is recorded, (3) metrics that missed targets have documented action items with named owners.
Questions (3)
Is a security metrics report produced at a defined cadence?
Metrics should be compared against defined targets and show trend data. Reports should be addressed to or acknowledged by a named executive or security committee.
Which of the following security metrics does your organisation actively track and report?
A good metrics programme covers at least training completion, vulnerability remediation SLA, and incident rates, with results compared to defined targets each reporting period.
Which of the following does the security metrics report carry?
Options run from the most commonly present to the least. A value with no target is a number. A report with no named recipient has no reader accountable for acting on it.