ciso.diy
Security Metrics & KPI Library preview
Governance security metricsKPIKRIboard reporting

Security Metrics & KPI Library

Stop reporting patch counts. 86 defined metrics with formulas, source systems, starting targets and an anti-gaming note each, mapped to CSF 2.0 / ISO 27001 / CIS v8 / SOC 2 and to the regimes that pull them — plus the twelve to start with at any maturity, a protection-level sheet that turns targets into priced decisions the board owns, and a dashboard that rolls one data-entry sheet into board, exec and ops views.

What this actually gives you

  • 86 metrics, not 100 — deliberately. Padding to the spec would have meant vanity metrics, which the guide spends a section arguing against.
  • Every metric carries a formula, the source system, a starting target, a lead/lag flag, framework mappings, regulatory pull, industry flags and an anti-gaming note saying how that specific number gets fudged.
  • The twelve are the same list three ways: the insurable baseline, the NYDFS certification core, and what examiners ask for first — so a new leader, an underwriter and an examiner look at one list rather than three.
  • Protection levels turn targets into decisions: the sheet records cost-to-hold and the business owner who agreed, so “MTTR four hours versus one hour” becomes a priced option the board owns rather than a target the CISO wishes for.
  • Denominators come from the inventory, never from the tool. 98% EDR coverage measured across the machines EDR already knows about is a tautology, not coverage.

Most security metrics programmes report what is easy to count. Patch counts, ticket volumes, training completion — numbers that go up and to the right and tell a board nothing about whether the company is protected.

Eighty-six metrics, not a hundred. The spec said a hundred; padding to it would have meant vanity metrics, and the guide spends a section arguing against exactly those. Every one of the 86 carries a definition, a formula, the source system, a cadence, a unit, a starting target, a lead-or-lag flag, mappings to NIST CSF 2.0 / ISO 27001 / CIS v8 / SOC 2, its regulatory pull (DFS, SEC, DORA, NIS2, PCI, HIPAA, CMMC, CCPA, CRA, the AI Act, insurance), industry flags, and an anti-gaming note saying how that specific number gets fudged.

The twelve. A fixed core recommended at any maturity — and the reason it holds is that the same twelve are simultaneously the insurable baseline, the NYDFS certification core, and what examiners ask for first. They appear identically in the board deck, the selector and the day-75 task of The First 100 Days Kit, so a new leader, an underwriter and an examiner are looking at one list rather than three.

IAM-01 MFA everywhere · EDR-01 EDR coverage · RES-01 restore tests · RES-02 immutable backups · VUL-01 SLA remediation · VUL-02 KEV over 7 days · VUL-03 internet-facing exposures · TPR-01 vendors assessed · INC-02 notifications on time · INC-01 incidents trended · EDR-03 MTTR · GOV-05 maturity trended

Protection levels turn targets into decisions. This is the design choice that changes the board conversation. The PLA sheet records the current level, the proposed one, the cost to hold it, and the business owner who agreed — so "MTTR of four hours versus one hour" stops being a target the CISO wishes for and becomes an option with a price that the board chooses and owns. A declined option is a documented decision, which is worth as much as an approved one.

Denominators from the inventory, never from the tool. The runbook repeats it for every metric, because that is where most green metrics are quietly false: 98% EDR coverage measured across the machines EDR already knows about is not coverage, it is a tautology.

01 Metric Catalog + metrics.json (XLSX + JSON) — 86 metrics across 17 domains, typed KPI / KRI / ODM and tiered Board / Exec / Ops, with domain and regime indexes. The regime index is where the coverage shows: 31 metrics evidence NYDFS Part 500 alone. The JSON is the machine-readable twin for a BI tool or a pipeline.

02 Metric Selector & Protection Levels (XLSX) — maturity, industry, regimes, whether you build software and whether you run OT, in; a recommended pool out. Then the PLA sheet for the cost-and-owner conversation.

03 Dashboard Workbook (XLSX) — one data-entry sheet for twelve months rolls into latest value, trend arrow and RAG, then auto-filters into Board, Exec and Ops sheets. One entry point, three audiences.

04 Data-Collection Runbook (Markdown) — for every metric: which system it comes from, how to export it, how to compute it, and the trap. Plus source-system notes and a monthly close checklist.

05 Quarterly Board Metrics Deck (PPTX) — four questions and nothing else. Are we protected? Are we improving? Is anything outside appetite? What do you need to decide? With the trend chart and the protection-level options.

06 Practitioner Guide (PDF) — why metrics programmes fail, KPI versus KRI versus ODM, the three audiences, the twelve, selection, protection levels, denominators and gaming, the regime pull table, eight industry playbooks (financial, healthcare, SaaS, OT/manufacturing, public company, defense, retail, SMB-MSP) each naming what to add on top of the twelve, the pipeline, presenting, and the annual review.

Those playbooks are why one library serves a credit union, a medical-device manufacturer and a roofing roll-up without being rewritten for each.

Rules the library enforces. Definitions published and stable. Change the board set once a year, not once a quarter. Show composites with their components. Every RED or AMBER gets one sentence of explanation.

Feeds the board reports in SEC-01 and the NYDFS Part 500 Kit, the KRIs in ERR-01, and the vendor metrics in TPRM-01 and VRM-01.

Starting targets are starting points — defaults to argue with, not benchmarks you are held to.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 6