# SP-043 Security Metrics and Measurement

Status: active. Release 26.02. Modified 2026-02-10. Licence: CC BY-SA 4.0.

Scope: Architecture pattern for designing, implementing, and governing a security metrics programme that drives decision-making, demonstrates programme effectiveness, and closes the feedback loop across all security domains. Covers programme-level KPIs and KRIs, vulnerability management metrics (MTTR, patch coverage, SLA compliance), detection and response metrics (MTTD, MTTR, containment rate), offensive testing metrics...
Use when: Any organisation with a security programme that reports to executive management or the board. Organisations seeking to justify security investment through demonstrated outcomes.
Not when: Very small organisations where security is a part-time function and measurement overhead exceeds the value of the insight.

## Controls (19, NIST SP 800-53 ids)
- Critical (5): PM-06, PM-09, PM-14, CA-02, CA-07
- Important (10): PM-13, CA-05, CA-08, RA-03, RA-05, IR-04, IR-05, AU-06, SI-02, AT-02
- Standard (4): AU-02, SI-04, AT-03, PL-02

## What each critical control mitigates (5)
- PM-06 Measures of Performance: T-43-001, T-43-002, T-43-003, T-43-004, T-43-005, T-43-007, T-43-008, T-43-009, T-43-010, T-43-012
- PM-09 Risk Management Strategy: T-43-002, T-43-005, T-43-012
- PM-14 Testing, Training, and Monitoring: T-43-001, T-43-004, T-43-009, T-43-012
- CA-02 Control Assessments: T-43-001, T-43-008
- CA-07 Continuous Monitoring: T-43-003, T-43-007

## Threats and the controls that mitigate them (12)
- T-43-001 Goodhart's Law gaming — Security teams optimise for the metric rather than the outcome, producing impressive numbers that mask deteriorating security posture (closing tickets without investigation, patching low-risk items first, sending obviously fake phishing simulations): PM-06, CA-02, PM-14
- T-43-002 Vanity metrics — Organisation measures and reports activity metrics (scans run, trainings completed, policies published) that demonstrate effort but provide no signal about actual risk reduction or programme effectiveness: PM-06, PM-09, RA-03
- T-43-003 Green dashboard syndrome — Metric aggregation and threshold design produces an overall 'green' status that conceals critical red areas, giving executives false confidence in security posture while significant risks remain unaddressed: PM-06, CA-07, AU-06
- T-43-004 Measurement without action — Organisation collects and reports comprehensive security metrics but has no governance mechanism to trigger corrective action when metrics deteriorate, reducing the programme to expensive data collection: PM-06, PM-14, CA-05
- T-43-005 Executive misinterpretation — Operational metrics lose fidelity during translation to executive audiences, leading to misinformed investment decisions, inappropriate risk acceptance, or disproportionate response to low-priority issues: PM-06, PM-09, PL-02
- T-43-006 Metric data integrity compromise — Attacker or insider manipulates the data sources feeding security metrics (vulnerability scanner results, SIEM logs, ticketing system records) to conceal real security deficiencies or ongoing compromise: AU-06, AU-02, SI-04
- T-43-007 Coverage blind spots — Metrics programme measures only assets, systems, or processes within its visibility, creating a false sense of comprehensive security while shadow IT, unmanaged endpoints, or unscanned networks remain invisible: CA-07, RA-05, PM-06
- T-43-008 Lagging indicator dependency — Organisation relies exclusively on backward-looking metrics (incidents occurred, breaches detected) rather than leading indicators (control coverage, vulnerability exposure), failing to predict and prevent future risk: PM-06, RA-03, CA-02
- T-43-009 Benchmark manipulation — Organisation selects favourable benchmark comparisons (smaller peers, broader industry averages, outdated datasets) to present artificially positive positioning rather than honest assessment of relative security posture: PM-06, PM-14, RA-03
- T-43-010 Alert fatigue from metric overload — Security teams drown in too many metrics, dashboards, and reports, losing the ability to distinguish signal from noise and ultimately ignoring metrics entirely, including those indicating genuine risk escalation: PM-06, SI-04, AU-06
- T-43-011 Perverse incentive from punitive measurement — Metrics used to punish individuals (naming phishing clickers, blaming teams for findings) drive behaviour underground: employees stop reporting incidents, teams stop disclosing vulnerabilities, and the organisation loses visibility into its actual risk posture: AT-02, PM-13, IR-04
- T-43-012 Measurement cost exceeding value — The metrics programme consumes disproportionate security resources (analyst time for manual data collection, expensive GRC tooling, reporting overhead) that would deliver more risk reduction if spent on actual security improvement: PM-06, PM-09, PM-14

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-043/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-043/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 32 KB: /api/v1/patterns/SP-043
- Page for people: /patterns/sp-043/
- Related: SP-038 Vulnerability Management and Patching; SP-031 Security Monitoring and Response; SP-035 Offensive Security Testing; SP-036 Incident Response; SP-014 Awareness and Training Pattern; SP-018 Information Security Management System; SP-042 Third Party Risk Management; SP-034 Cyber Resilience

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
