Skip to content

Dwell Time

What is Dwell Time?

The duration between when a threat actor gains initial access to a system and when the breach is detected, a key security performance metric.

Information Security

What the standards actually require on dwell time

Requirements naming dwell time across 2 standards, quoted from the control text.

Refresh organizational systems and system components from a known, trusted state at a defined frequency to reduce dwell time and persistence of malicious code.

3.14.4e · Refresh Systems and Components from a Trusted Baseline

Report incident metrics including dwell time, mean time to detect, mean time to contain, mean time to recover, financial impact, and lessons trend analysis to executive risk committees.

PICERL-L-03 · Lessons Learned: Metrics and Reporting to Executives

Questions people ask about dwell time

What is Dwell Time?
The duration between when a threat actor gains initial access to a system and when the breach is detected, a key security performance metric.
Why is Dwell Time important for compliance?
Dwell Time is a key concept in Information Security. Understanding dwell time helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Dwell Time?
Dwell Time appears in the requirement text of NIST SP 800-172, SANS Incident Handler's Handbook and PICERL Methodology. Across these standards we have identified 2 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Dwell Time?
Explore our compliance framework pages to see how dwell time applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Dwell Time applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.