Communicate Incident Response Metrics and KPIs Flashcards

1
Q

MTTD

A

Mean time to detect - a measurement of the average time from when an incident starts and the time taken to become aware of the vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

MTTI

A

Mean time to identify - The average measure of time for the initial response to a potential security incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

MTTR

A

Mean time to respond - a measurement of the average time taken for the initial response to a potential security incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

MTTC

A

Mean time to contain - a measurement of time to quarantine a potential security incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

MTTR (Remediate)

A

Mean time to remediate - a measurement of the average time taken to close the vulnerability that triggered the incident response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

MTTR (Recover)

A

Mean time to recovery - a measurement of the average time it takes to restore operations to a pre-security incident state.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Alert Volume

A

Alert volume - the amount of notifications indicating a potential security incident. The greater the amount of notifications can lead to “alert fatigue”. It can be challenge to determine the critical alerts from low priority alerts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly