As we are constantly being told, good Security metrics should have a clear link with business objectives and goals. However it is always a challenge to translate the security metrics into something that will be of interest to the Executive and most importantly drive a decision or contribute to an outcome.
The Gartner report titled Five Required Characteristics of Security Metrics that was refreshed in 2015 has some good advice. However, I would like to hear from CISOs that feel they have good reporting and metrics in place in the real world that the Executive team understand and perhaps set up a call discuss if there is interest.
Regards
Phil
Thanks Wes for your reply.
One of the things I am attempting to do is to take it up a level and remove the technical results from the Executive reporting (It is fine for the Tech audience, such as the direct reports of the CIO). I quite like the approach of the Info security metrics group whereby they roll up all the various metrics into 3 categories of EXPOSURE, AGILITY and CULTURE. I am also reading a book by Andrew Jaquith called Security Metrics: Replacing Fear, Uncertainty, and Doubt which has a very good approach.
Has anyone else got some examples of what they feel works for them?
Thanks
Phil