Cybersecurity metrics that matter (and how to measure them)
ID: eec30056-141b-515b-acef-593718d7a77b
STIX ID: report--eec30056-141b-515b-acef-593718d7a77b
Feed Name: Red Canary
This article provides guidance on SOC success metrics, emphasizing accuracy, volume, and timeliness while cautioning that mean-time-to-* metrics can be misleading without standardized definitions and context. It recommends using medians over means, clearly defining when the measurement clock starts and stops for detect/respond/mitigate, and distinguishing dwell time from breakout time, advocating for consistent, transparent methodologies to make time-based metrics meaningful.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
