
April 18, 2019 • Garrett Garitano
You need to measure success in IT security. If you don’t, your requests for tools, resources, and budgets are going to be ignored. That’s not the only reason; measuring IT security through KPIs helps you perform better as a manager. You can recognize staff excellence by pointing to their performance and help them advance in […]
You need to measure success in IT security. If you don’t, your requests for tools, resources, and budgets are going to be ignored. That’s not the only reason; measuring IT security through KPIs helps you perform better as a manager. You can recognize staff excellence by pointing to their performance and help them advance in their careers.
There’s one final reason you need to develop IT security maintenance key performance indicators. When everything is going smoothly in IT security, KPIs demonstrate your proactive efforts to maintain the organization. Without them, you face an “out of sight, out of mind” challenge in that IT security becomes invisible until the next crisis occurs.
1. Patch Management Key Performance Indicator
Overview: Every month, Microsoft and other technology providers release updates and patches to their software. Many of these updates are designed to eliminate security vulnerabilities. However, these patches only provide value if you implement them quickly on all your systems. If you act slowly, you face increased hacking risk exposure.
Example KPI thresholds:
Estimated work effort and resources:
Tip: Define the scope of this KPI to focus on the most critical systems. For example, consider focusing the KPI on your servers first.
2. Inactive User Account Management Key Performance Indicator
Overview: Every year, employees change roles and leave your organization. As a result, you’ll start to have inactive user accounts. Since they’re inactive, they’re unlikely to be managed well. That’s why we recommend tracking this risk exposure over time to see if your organization is addressing this exposure.
Example KPI thresholds:
Estimated work effort and resources:
3. End User Security Experience Key Performance Indicator
Overview: Traditionally, IT security leaders haven’t emphasized the end user experience. They imposed security restrictions, and users simply had to live by those rules. Unfortunately, this rule enforcement attitude means that some users resent IT and will avoid IT governance by using cloud services and other non-recommended solutions. That’s why we recommend designing a KPI to measure the end user experience.
Example KPI thresholds:
Estimated work effort and resources:
You’ll need a survey tool such as SurveyMonkey to gather responses from end users. Additionally, you’ll need support from an IT analyst to design the survey, promote it, and prepare the KPI reporting.
What Other KPIs Could You Include?
The above three KPIs are three ways to monitor and evaluate IT security maintenance performance. However, large organizations may have a need to develop additional measures. In those cases, look at measuring the following areas:
Single Sign-On (SSO) coverage: Measure what percentage of your systems and cloud services are covered by your Single Sign-On software solution.