Skip to content

Latest commit

 

History

History
77 lines (44 loc) · 2.34 KB

File metadata and controls

77 lines (44 loc) · 2.34 KB

Metrics

Category Metric id Title SLO Weight
Software Development
development_vulnerabilities Software repositories without critical vulnerabilities 98.00% - 99.00% 0.8
Identity Management
identity_credentials Identity - Aged Credentials 98.00% - 99.00% 0.8
identity_dormant Identity - Inactive Identities 98.00% - 99.00% 0.8
User Security
user_awareness Users with awareness training completed 80.00% - 90.00% 0.4
Vulnerability Management
vulnerabilities_critical Systems with Critical and High vulnerabilities 80.00% - 95.00% 0.8
vulnerabilities_critical_patching Critical vulnerabilities patched within SLO 80.00% - 95.00% 0.8

List of metrics

Software repositories without critical vulnerabilities

Metric id Category SLO Weight
development_vulnerabilities Software Development 98.00% - 99.00% 0.8

Software repositories without critical vulnerabilities

Identity - Aged Credentials

Metric id Category SLO Weight
identity_credentials Identity Management 98.00% - 99.00% 0.8

Ensure that all user accounts change their passwords regularly.

Identity - Inactive Identities

Metric id Category SLO Weight
identity_dormant Identity Management 98.00% - 99.00% 0.8

Ensure that all user accounts are active and in use.

Users with awareness training completed

Metric id Category SLO Weight
user_awareness User Security 80.00% - 90.00% 0.4

This metric demonstrates the users that have completed the security awareness training within the last 12 months.

Systems with Critical and High vulnerabilities

Metric id Category SLO Weight
vulnerabilities_critical Vulnerability Management 80.00% - 95.00% 0.8

Ensure that all systems do not have any urgent vulnerabilities that can impact the risk.

Critical vulnerabilities patched within SLO

Metric id Category SLO Weight
vulnerabilities_critical_patching Vulnerability Management 80.00% - 95.00% 0.8

Ensure that all systems do not have any urgent vulnerabilities that can impact the risk.