Security Metrics
Security metrics turn observations about controls, incidents, assets, and risk into defined measures. They help an organization judge whether safeguards are present, working, timely, and improving without confusing activity counts with security outcomes.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Security Metrics
Security metrics are how raw security observations become a reason to make a decision. Before them, an organization has patch tickets, scanner findings, incident timestamps, and dashboards full of confident colors. After them, it can say what population a number describes, what it does not describe, and who has to do something next. This is less glamorous than it sounds, which is fortunate. Glamour has caused enough trouble already.
The useful shape is decision, definition, observation, and action. Start with the question that needs answering. Define the measure before collecting it. Then gather observations, calculate the value, add scope and uncertainty, and report the action path. A chart arrives near the end, after the work that prevents it from lying with excellent typography.
The surprise is the denominator. A patch percentage looks reassuring until you ask which assets were included. If the inventory misses unmanaged systems, a high percentage describes the known inventory, not the environment. The number is not necessarily wrong. It has merely been asked to wear a larger hat than it owns.
This is also why one metric travels with companions. Fast remediation can coexist with an old critical backlog. An alert count can rise because detection coverage improved. Pair a rate with coverage, age, severity, and exceptions so a favorable value cannot hide the exposure that matters. A KPI tracks progress toward an objective; a KRI signals proximity to a risk threshold. Either needs an owner and a response, or it is an acronym looking for a meeting.
Data quality is part of the result. Check completeness, accuracy, consistency, timeliness, and lineage before interpreting a trend. If a source or definition changes, version it. Otherwise, one graceful line graph may join values that mean different things, which is an impressive visual effect but not analysis.
Read the Introduction for the full measurement path and its limits. Use the Slides for the relationships between observation, measure, indicator, and action. Keep the Cheatsheet nearby when defining formulas, populations, thresholds, and metric pairs. The Practice section turns the idea into a small exposure report. Field Notes covers the operational traps that a well-polished dashboard prefers not to mention.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/55/v1/final
Supports
- Security measure purpose, types, selection, prioritization, and evaluation
- Quantitative and qualitative assessment
- Implementation, effectiveness, efficiency, and impact measurement
- Quiz answers and reference-path rationale
- 2024 timeline milestone
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-55v1.pdf
Supports
- Measure documentation, scope, aggregation, data management, data quality, and uncertainty
- Statistical analysis concepts and interpretation limits
- Definition records, versioning, denominators, and reporting context
- https://csrc.nist.gov/pubs/sp/800/55/v2/final
Supports
- Measurement-program purpose, roles, workflow, communication, and corrective action
- Quiz answer on program workflow
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-55v2.pdf
Supports
- Five-activity measurement-program workflow
- Program integration with business activities and risk management
- https://csrc.nist.gov/pubs/sp/800/55/r1/final
Supports
- 2003 original publication and 2008 Revision 1 dates
- Historical purpose of performance measurement guidance
- https://csrc.nist.gov/Projects/measurements-for-information-security/publications
Supports
- 2009 Directions in Security Metrics Research milestone
- 2018 Bad Security Metrics research milestones
- https://csrc.nist.gov/pubs/sp/800/137/final
Supports
- Continuous visibility into assets, threats, vulnerabilities, and control effectiveness
- Risk-tolerance relationship and 2011 timeline milestone
- Reference-path rationale
- https://csrc.nist.gov/pubs/sp/800/137/a/final
Supports
- Continuous-monitoring program assessment
- 2020 timeline milestone
- https://www.nist.gov/cyberframework
Supports
- CSF 2.0 outcome structure, Profiles, and reference-path rationale
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- 2014 CSF 1.0 release, Core, Tiers, and Profiles
- https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
Supports
- 2024 CSF 2.0 release and expanded governance scope
- https://www.nist.gov/news-events/news/2024/12/measurement-guide-information-security-nist-releases-volumes-1-and-2-sp-800
Supports
- December 2024 two-volume release and major update areas
- https://www.cisa.gov/cybersecurity-performance-goals
Supports
- Prioritized measurable baseline practices and CSF alignment
- 2022 timeline milestone and reference-path rationale
- https://www.cisecurity.org/controls/cis-controls-list
Supports
- Concrete safeguard catalog for implementation and effectiveness questions
- Reference-path rationale
- https://github.com/sindresorhus/awesome
Supports
- Discovery route to the Awesome Security list
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Wazuh, OpenVAS, Security Onion, and Zeek as security observation sources
- https://documentation.wazuh.com/current/user-manual/capabilities/index.html
Supports
- Endpoint, configuration, vulnerability, and compliance observation capabilities
- Awesome Links rationale
- https://greenbone.github.io/docs/latest/
Supports
- Vulnerability management observations and workflows
- Awesome Links rationale
- https://docs.securityonion.net/
Supports
- Network and host visibility, alert, and case-management observations
- Awesome Links rationale
- https://docs.zeek.org/en/current/
Supports
- Structured network logs and interpretation guidance
- Awesome Links rationale
- https://panaseer.com/platform/continuous-controls-monitoring
Supports
- Panaseer landscape placement and control-measurement workflow
- https://www.servicenow.com/docs/r/environmental-social-governance/metrics-overview.html
Supports
- ServiceNow GRC Metrics definitions, collection, targets, and reporting
- ServiceNow landscape placement
- https://www.metricstream.com/products/it-and-cyber-risk-management.htm
Supports
- MetricStream landscape placement and cyber-risk aggregation
- https://www.archerirm.com/
Supports
- Archer landscape placement and integrated risk context
- https://www.bitsight.com/security-ratings
Supports
- Bitsight landscape placement and external rating scope
- https://securityscorecard.com/trust/
Supports
- SecurityScorecard landscape placement, rating transparency, and observable-data limits
- https://www.mastercard.com/us/en/business/cybersecurity-fraud-prevention/riskrecon.html
Supports
- RiskRecon landscape placement and external third-party measurement
- https://blackkite.com/
Supports
- Black Kite landscape placement and third-party risk measurement
- https://safesecurity.com/
Supports
- SAFE landscape placement and modeled cyber-risk exposure
- https://www.risklens.com/
Supports
- RiskLens landscape placement and FAIR-based quantification
