The Metrics Story

The Metrics Story

Metrics help to tell a story and tell that story to the right audience. When I present on this topic I use an image showing a child, a spouse, and grandparent. All three can ask the same question, “How was work?”, and all three will receive an answer with a different story. Each will receive details that are appropriate for their level of understanding and their background. The story that, we as CIOs and CISOs, need to tell is no different. We have different audience members that include: the Board, Executives, Auditors, and Engineers. As we tell each of these audiences the story of IT and information security we need to keep in mind their background and the ask. 

The Board is strategic and we are asking for resources. The Board might be comfortable with that functional level aggregation or they may want a single score. When a single score is needed this is usually around a maturity level and it should be coupled with a risk rating. Combined, these can tell where you are and how tight the controls are.

Engineers need the details and we are going to ask them to fix something. With the Engineers we can show them detailed tactical metrics. NIST and CIS have a great listing of tactical metrics with parameters for different levels of risk. From there, you can tie the results to technology. 

Auditors need to know we know about our environment and that we’re doing something about it. Auditors would need to need to see that we are headed in the right direction. 

Executives need actionable information, usually, by subject area and we need to answer their ask, “what’s in it for me?” Executives need to see how the security program is affecting them. We need to aggregate by topics they care about. For example, the CMO might care about Integrity and Reputation, to address concerns of report accuracy and potential reputation damage. 

Your metrics are not a burden to the job but should be a tool to help you tell a better story.

要查看或添加评论,请登录

Edward Marchewka的更多文章

  • The Story is What Matters

    The Story is What Matters

    Several scholarly sources have stressed that better communication with the board is needed (Al-Moshaigeh et al., 2019;…

    1 条评论
  • Risk Communication: Reducing Affective Response

    Risk Communication: Reducing Affective Response

    Failure to communicate risks effectively results in executives and boards making inappropriate risk decisions (Hooper &…

  • Close the Gap

    Close the Gap

    Wachnik (2014) and Bergh et al. (2019) defined information asymmetry as a situation where one party has more…

    1 条评论
  • Selecting the Right Tool

    Selecting the Right Tool

    There are some posts and books that say risk matrices are worse than useless and often cite Cox (2008) and Cox & Popken…

    2 条评论
  • 1,460 Days Later

    1,460 Days Later

    I talk often about telling a better story and telling YOUR story. So here is a little into mine.

  • Understanding Negotiation

    Understanding Negotiation

    My kids have been into The Greatest Showman lately, so I get to see it a lot. And my wife downloaded both soundtracks…

  • Aggregate

    Aggregate

    I have written several articles with an emphasis on aggregation of metrics. Presenting tactical metrics will go over…

  • Your Next Board Meeting

    Your Next Board Meeting

    It is the end of Q1-2019 for those following the calendar year. Please permit me to ask this questions, How did your…

  • You Need to Tell a Story

    You Need to Tell a Story

    We've heard this mantra over and over again on you need to tell a story but I haven't seen this broken down in a…

  • IT is in the Name

    IT is in the Name

    Information Technology at the functional level has become a commodity. People expect to come into work, sit down at…

社区洞察

其他会员也浏览了