SEF-05: Are information security incident metrics established and monitored?
Organizations should define, implement and monitor metrics associated with events and incidents to detect any weaknesses in the operational processes or technical controls which support effective incident management. Metrics may quantify: a. Volume of events and ratio of events to incidents. b. Incidents by type, product, department, severity, etc. c. Timeliness of procedural execution for identification, investigation, and resolution. d. Variances from documented procedures.
Control implemented
Control ownership
Description
Establish and monitor information security incident metrics.