Incident Metrics
What is Incident Metrics?
Quantitative measures used to track and evaluate the frequency, severity, response time, and cost of security incidents.
Terms that appear alongside incident metrics
Each of these is named in at least one of the same controls as incident metrics. The number is how many controls name both.
- nist 2 shared controls
- risk reporting 2 shared controls
- phishing 2 shared controls
- compliance 2 shared controls
- phishing simulation 2 shared controls
- audit 2 shared controls
- continuous improvement 2 shared controls
Frameworks that govern incident metrics
What the standards actually require on incident metrics
Requirements naming incident metrics across 3 standards, quoted from the control text.
Operate third-party risk + supply chain + resilience + metrics + continuous improvement per NRF framework. Third-party risk must (a) maintain vendor inventory categorised by data access + critical service + payment processing + e-commerce platform + cloud serv...
NRFCS-8 · Third-Party Risk, Supply Chain, Vendor Management, Resilience, Peak-Season Readiness, Metrics, Continuous Improvement →Operate metrics + monitoring + continuous improvement + maturity per OSFI B-13 Domain 6 + cross-cutting expectations. Metrics, Monitoring and Continuous Improvement must (a) maintain technology and cyber risk metrics covering control coverage + maturity + inci...
OSFIB13-8 · Metrics, Monitoring, Continuous Improvement, Maturity →Report incident metrics including dwell time, mean time to detect, mean time to contain, mean time to recover, financial impact, and lessons trend analysis to executive risk committees.
PICERL-L-03 · Lessons Learned: Metrics and Reporting to Executives →Questions people ask about incident metrics
What is Incident Metrics?
Why is Incident Metrics important for compliance?
Which compliance frameworks address Incident Metrics?
Where can I learn more about Incident Metrics?
See how Incident Metrics applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.