CIS Consensus Information Security Metrics
- Free/open
- Registration
* Application Security
o Number of Applications
o Percentage of Critical Applications
o Risk Assessment Coverage
o Security Testing Coverage
* Configuration Change Management
o Mean-Time to Complete Changes
o Percent of Changes with Security Review
o Percent of Changes with Security Exceptions
* Financial
o Information Security Budget as % of IT Budget
o Information Security Budget Allocation
* Incident Management
o Mean-Time to Incident Discovery
o Incident Rate
o Percentage of Incidents Detected by Internal Controls
o Mean-Time Between Security Incidents
o Mean-Time to Recovery
* Patch Management
o Patch Policy Compliance
o Patch Management Coverage
o Mean-Time to Patch
* Vulnerability Management
o Vulnerability Scan Coverage
o Percent of Systems Without Known Severe Vulnerabilities
o Mean-Time to Mitigate Vulnerabilities
o Number of Known Vulnerability Instances





