close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel

CIS Consensus Information Security Metrics

Issuer Full Name
Center for Internet Security (CIS)
Issued
11 May 2009
Country:
Type
  • Free/open
  • Registration
Keywords
Meta Description
T2P Ruleshub resource reference: CIS Consensus Information Security Metrics
A set of key security outcome and practice metrics developed by a team of more than 150 government, private, and academic experts. Metrics cover the following business functions:

* Application Security
o Number of Applications
o Percentage of Critical Applications
o Risk Assessment Coverage
o Security Testing Coverage

* Configuration Change Management
o Mean-Time to Complete Changes
o Percent of Changes with Security Review
o Percent of Changes with Security Exceptions

* Financial
o Information Security Budget as % of IT Budget
o Information Security Budget Allocation

* Incident Management
o Mean-Time to Incident Discovery
o Incident Rate
o Percentage of Incidents Detected by Internal Controls
o Mean-Time Between Security Incidents
o Mean-Time to Recovery

* Patch Management
o Patch Policy Compliance
o Patch Management Coverage
o Mean-Time to Patch

* Vulnerability Management
o Vulnerability Scan Coverage
o Percent of Systems Without Known Severe Vulnerabilities
o Mean-Time to Mitigate Vulnerabilities
o Number of Known Vulnerability Instances
Rate this rule
0 vote
Favored:
0