When developing information-security metrics, the MOST important consideration is that the metrics:
Information-security metrics should provide actionable data so management and security teams can identify conditions that require attention, prioritize improvements, and take effective corrective action.
Community Discussion