Tutorial 3: Security Program Measurement

Unit 8 ยท Governance, risk, and capstone

Objectives

A metric is a defined measurement; an indicator supports interpretation; a target guides action. Measure whether critical assets are covered, controls operate, attacks are detected, remediation happens, and recovery works. Avoid optimizing a number at the expense of the underlying outcome.

measure: critical vulnerabilities older than 30 days
context: internet exposure, exploitability, asset owner
action: remediation or documented risk acceptance

Executive reports should connect trend to risk, owner, decision, and investment. Technical dashboards can show control coverage and evidence freshness. Include sampling limits, blind spots, and changes in measurement so a reported improvement is not mistaken for actual risk reduction.

Exercises

  1. Design a dashboard for privileged access.
  2. Replace three activity metrics with outcome measures.
  3. Explain uncertainty in a coverage percentage.

Self-check

  1. What is a target?
  2. Why include context?
  3. What is a blind spot?

Self-Check Quiz

1. Is 100% tool deployment the same as 100% protection?

AnswerNo. Deployment does not prove correct configuration, coverage, operation, or effective response.

2. What should a metric drive?

AnswerA decision, action, or risk conversation rather than measurement for its own sake.

Homework

  1. Design a quarterly security scorecard.
  2. Define data sources, owners, targets, and limitations.
  3. Recommend three decisions from the trends.
Sample answerUse measures such as privileged MFA coverage, overdue critical exposure, access-review completion, detection precision, restore-test success, and time to revoke access. Each has a source, owner, time period, target, and limitation; trends should lead to funded remediation or explicit risk decisions.