GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-023 Security Measures Performance Measurement

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A security metrics report is produced at a defined cadence covering at minimum security training completion, vulnerability remediation against its defined service level, security incident rate and audit finding closure. Each metric carries a defined target and its current value against that target, with the trend across prior periods. The report names the executive or committee it is delivered to and records their acknowledgement.

Rationale

A programme with no measured outcome cannot show improvement or argue for resource. The metrics are also the numbers an external assurance report quotes. The four named metrics are the floor because each has an owning control that already produces the number: HRS-004 for training completion, INF-007 for vulnerability remediation, INC-001 for incidents and GOV-011 for audit findings. Application-level security metrics and privacy accountability reporting are not required here.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (18)

AIS-03Application Security Metricspartial
DCS-17Datacenter Metricsinformative
GRC-02Risk Management Programinformative
TVM-12Vulnerability Management Metricsinformative
AIS-03Application Security Metricspartial
DCS-17Datacenter Metricsinformative
GRC-02Risk Management Programinformative
TVM-12Vulnerability Management Metricsinformative
NIS2-Art.21.2.fAssessment of the Effectiveness of Risk-Management Measuresinformative
NIS2-CIR-1.1Policy on the Security of Network and Information Systemsinformative
NIS2-CIR-2.2Compliance Monitoringinformative
NIS2-CIR-7Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measuresinformative
AT-6Training Feedbackinformative
PM-27Privacy Reportingpartial
PM-6Measures of Performancefull
MS-2.7-004AI System Security and Resilience Evaluation | MS-2.7-004full
CC2.1COSO Principle 13: Uses Relevant Informationpartial
CC4.1COSO Principle 16: Conducts Ongoing or Separate Evaluationsinformative

Evidence (2)

reportdocumentmanual

Security metrics report showing defined KPIs covering control effectiveness, risk posture, training completion, and incident rates, reported to management.

Example: Monthly or quarterly security metrics report (Confluence / GRC dashboard export / PDF), showing: metric name, target, current value, trend, and reporting period, distributed to named management recipients.

Test: Request the last two security metrics reports. Verify: (1) reports are produced within the defined cadence, (2) metrics cover at minimum: training completion rate, open vulnerability count or SLA compliance, incident rate, and audit finding closure rate, (3) current values are compared to targets, (4) the report is addressed to or acknowledged by a named executive or security committee.

recorddocumentmanual

Evidence that metrics results have been acted on: meeting minutes or action log showing management reviewed metrics and assigned follow-up items.

Example: Security committee or management meeting minutes (Google Drive), referencing the metrics report, showing: the date of review, attendee list including named management, and any action items generated from metric results.

Test: Request meeting minutes from the most recent security metrics review. Verify: (1) metrics were discussed, (2) at least one management-level attendee is recorded, (3) metrics that missed targets have documented action items with named owners.

Questions (3)

boolean

Is a security metrics report produced at a defined cadence?

Metrics should be compared against defined targets and show trend data. Reports should be addressed to or acknowledged by a named executive or security committee.

multi

Which of the following security metrics does your organisation actively track and report?

Security awareness training completion rateMean time to remediate (MTTR) for open vulnerabilities or findingsSecurity incident count and trendAudit finding closure ratePhishing simulation click rateRisk register aging (open risks past target date)None of the above

A good metrics programme covers at least training completion, vulnerability remediation SLA, and incident rates, with results compared to defined targets each reporting period.

multi

Which of the following does the security metrics report carry?

A defined target for each metricThe current value against that targetThe trend across prior reporting periodsThe executive or committee it is delivered to, namedA record of that recipient's acknowledgementNone of the above

Options run from the most commonly present to the least. A value with no target is a number. A report with no named recipient has no reader accountable for acting on it.