Communicate Incident Response Metrics and KPIs Flashcards
MTTD
Mean time to detect - a measurement of the average time from when an incident starts and the time taken to become aware of the vulnerability.
MTTI
Mean time to identify - The average measure of time for the initial response to a potential security incident
MTTR
Mean time to respond - a measurement of the average time taken for the initial response to a potential security incident.
MTTC
Mean time to contain - a measurement of time to quarantine a potential security incident
MTTR (Remediate)
Mean time to remediate - a measurement of the average time taken to close the vulnerability that triggered the incident response
MTTR (Recover)
Mean time to recovery - a measurement of the average time it takes to restore operations to a pre-security incident state.
Alert Volume
Alert volume - the amount of notifications indicating a potential security incident. The greater the amount of notifications can lead to “alert fatigue”. It can be challenge to determine the critical alerts from low priority alerts.