ISO27k Security Metrics Examples
ISO27k Security Metrics Examples
4 Risk mgmt
8 HR 12 SDLC
Relevant section/s 5 Security policy
9 Physical security 13 Incident mgmt
of ISO/IEC 27002
6 Information security
10 Comms/Ops mgmt 14 Continuity mgmt
Main Subsidiary governance
11 Access control 15 Compliance
7 Asset mgmt
Objective / Subjective / Semi*
Leading / Lagging / Semi
Nature of metric Absolute / Relative (trend) / Semi
Soft / Hard / Semi
Confidentiality / Integrity / Availability
Notes
Title/name of metric Payroll data quality
Rationale for Modern analogue of the old “Days since a lost time
measuring this safety incident” boards outside factories
Frequency Annual
Customer insecurities could introduce viruses,
create data integrity problems and result in
Rationale for unauthorized disclosure of information affecting
measuring this the organization. Less sophisticated/security
aware customers are likely to have less effective
security controls.