CIS Security Metrics Available

June 27th, 2009 by kartar Leave a reply »

The CIS has released a collection of metrics – CIS Security Metrics Guide (v. 1.0.0).  The project goal to “develop a balanced combination of unambiguous and logically defensible outcome and practice metrics measuring” and to “utilize data commonly available in most enterprises.”

The following metrics are proposed and documented:

  • Application
    • Number of Applications
    • Percentage of Critical Applications
    • Risk Assessment Coverage
    • Testing Coverage
  • Configuration Change Management
    • Mean-Time to Complete Changes
    • Percent of Changes with Review
    • Percent of Changes with Exceptions
  • Financial
    • Information Budget as % of IT Budget
    • Information Budget Allocation
  • Incident Management
    • Mean-Time to Incident Discovery
    • Incident Rate
    • Percentage of Incidents Detected by Internal Controls
    • Mean-Time Between Incidents
    • Mean-Time to Recovery
  • Management
  • Vulnerability Management
    • Vulnerability Scan Coverage
    • Percent of Systems Without Known Severe Vulnerabilities
    • Mean-Time to Mitigate Vulnerabilities
    • Number of Known Vulnerability Instance”

Download the metrics here or via direct PDF link.

Leave a Reply