Aggregate

Aggregate

I have written several articles with an emphasis on aggregation of metrics. Presenting tactical metrics will go over most peoples' heads or they simply don't need to know the tiny details that tactical metrics provide. Something that I have been asked to clarify is, how does aggregation relate to the business?

While having a discussion with a fellow information security practitioner we were saying that a dashboard is like a scoreboard. You have to understand the game and what each stat means to know that state of the game. However, the dashboard, like a scoreboard, shouldn't be so complicated that you can't watch the game which is where aggregation comes into play.

With that, here are two examples of using aggregation to relate aggregated results to the business using the C.H.I.C.A.GO. framework:

  • Education
  • Confidentiality - This area relates to protecting student data. A loss of confidentiality puts federal funding at risk due to a potential FERPA violation.
  • Human Resources - This is all about productivity of people. Are they inconvenienced? Are they able to work? Can teachers deliver their lessons?
  • Integrity - Reporting has to happen to ensure students are where they are supposed to be along with other student data. Also, state funding is related to reporting. A failure in this space puts additional funding at risk.
  • Character/Reputation - A loss, usually related to another KRI, in this space results in a loss of confidence. In the education space, parents can move to private or charter schools. This also can result in having to deal with the press or lawsuits.
  • Availability - Schools spend money on technology and it should be available. When public funds are used the public usually wants it used in the classroom. Nobody wants a call from the Mayor, trustee, or alderman asking about misappropriation or waste of funds.
  • Gold/Finance - Educational institutions have to be mindful of their dollars and cents. Ensuring that money is spent wisely and not wasted on fines or preventable issues helps to keep this risk in check.
  • Healthcare
  • Confidentiality - This is about protecting patient and employee data. Loss of patient data is most likely a HIPAA violation which directly relates to fines and bad press.
  • Human Resources - Here we are ensuring that doctors and staff are productive and can do their jobs of saving and enhancing lives.
  • Integrity - Reporting in healthcare is incredibly important. Providing care is based on the patient records and history. A failure in this area can be catastrophic.
  • Character/Reputation - When a healthcare organization cannot be trusted people can move on to another provider. It also introduces extra scrutiny by outside parties which can be expensive to respond to.
  • Availability - Systems need to be up to provide care, from EMRs to connected MRI machines. We have seen in the press when healthcare falls victim to ransomware how quickly their operations can come to a halt.
  • Gold/Finance - No one wants fines or unnecessary costs. Funds not spent on patient care and boosting capabilities are not well spent.

However you aggregate your results make sure they tie back to what the business cares about. A simple way to answer, what does the business care about, is these quick questions:

  • What do we do and what do we need to do in order to do more?
  • Who do we do it for?
  • How do we do it?
  • When do we do what we do?
  • Why do we do what we do?

Through aggregation of the results we get the attention of the business by telling our story in terms that they understand. This helps get the results that you want to continue driving forward. From there, you can reverse the aggregation to know how to move forward tactically.

要查看或添加评论,请登录

Edward Marchewka的更多文章

  • The Story is What Matters

    The Story is What Matters

    Several scholarly sources have stressed that better communication with the board is needed (Al-Moshaigeh et al., 2019;…

    1 条评论
  • Risk Communication: Reducing Affective Response

    Risk Communication: Reducing Affective Response

    Failure to communicate risks effectively results in executives and boards making inappropriate risk decisions (Hooper &…

  • Close the Gap

    Close the Gap

    Wachnik (2014) and Bergh et al. (2019) defined information asymmetry as a situation where one party has more…

    1 条评论
  • Selecting the Right Tool

    Selecting the Right Tool

    There are some posts and books that say risk matrices are worse than useless and often cite Cox (2008) and Cox & Popken…

    2 条评论
  • 1,460 Days Later

    1,460 Days Later

    I talk often about telling a better story and telling YOUR story. So here is a little into mine.

  • Understanding Negotiation

    Understanding Negotiation

    My kids have been into The Greatest Showman lately, so I get to see it a lot. And my wife downloaded both soundtracks…

  • Your Next Board Meeting

    Your Next Board Meeting

    It is the end of Q1-2019 for those following the calendar year. Please permit me to ask this questions, How did your…

  • You Need to Tell a Story

    You Need to Tell a Story

    We've heard this mantra over and over again on you need to tell a story but I haven't seen this broken down in a…

  • IT is in the Name

    IT is in the Name

    Information Technology at the functional level has become a commodity. People expect to come into work, sit down at…

  • The Metrics Story

    The Metrics Story

    Metrics help to tell a story and tell that story to the right audience. When I present on this topic I use an image…

社区洞察

其他会员也浏览了