Security leaders rely on metrics both for internal management of the security function and for effective communication with business executives. Effective CISOs use meaningful metrics to build support for ZT across the organization and to avoid the trap of “precision without accuracy.”
Our research identified three stages for the effective use of metrics to assess and communicate security status and success:
1.Establish context.
Ensure that the organization is ready to use metrics effectively and frame the metrics in ways that resonate with their target audiences. The security team needs to have reached a reasonable level of achievement before metrics can help drive attention rather than concern. Target audiences need to understand what the metrics represent before they can absorb and discuss their implications. Additionally, the metrics themselves must speak to objectives or concerns held by each target audience. Colleagues will tune out metrics that they view as too abstract, “in the weeds,” or esoteric.