Security metrics are meant to provide insights to executive leadership (e.g., “are we more secure today than we were yesterday?”), but are often useless due to metrics / analytics reporting suffering from a Garbage In, Garbage Out (GIGO) problem.
Often GIGO issue is rooted in executives trying to explain their perceived needs for metrics to cybersecurity practitioners in a way that describes the design of a "football bat" (e.g., nonsensical solution).
Interestingly, security metrics are often a misnomer. When executives ask for metrics, they really want analytics (e.g., trending):
Analytics, not metrics, are designed to facilitate decision-making, evaluate performance and improve accountability through the collection, analysis and reporting of relevant performance related data. Security metrics / analytics can leverage:
KPIs:
KRIs: