Security metrics serve two purposes: they tell the operations team whether the security programme is working, and they tell the board and ISSC what the security posture is and whether it is improving. Metrics that serve only the first purpose (highly technical, actionable for engineers) are not suitable for ISSC reporting. Metrics that serve only the second (traffic-light summaries with no operational grounding) cannot drive security improvement. A well-designed security metrics framework serves both.
CTDISR-2025 Section 1 (governance and board reporting) and Section 17 (compliance monitoring) both require security metrics to be reported to the ISSC. The metrics you report, how they are calculated, and what decisions they drive are all elements an auditor may review.
Vulnerability Management Metrics
Mean Time to Remediate (MTTR) for vulnerabilities, measured separately by CVSS severity tier, is the primary vulnerability management metric. It tells you whether your remediation programme is meeting its own defined timelines (7 days for Critical, 30 days for High, 90 days for Medium) and trending in the right or wrong direction.
Calculate MTTR as the average time between when a vulnerability is identified in a scan and when it is confirmed remediated via re-scan, grouped by severity. A Critical MTTR of 45 days against a target of 14 days is an immediate action signal. An MTTR that is within target and trending downward indicates a functioning programme.
Vulnerability backlog is the count of open findings by severity tier at the end of each reporting period. Track this as a trend: a backlog that grows month over month despite remediation activity indicates that the rate of new findings is exceeding the rate of remediation, which requires either faster remediation or additional resource.
Patch compliance rate for internet-facing infrastructure is the percentage of critical and edge systems running current patched firmware and software within your defined patching window. Track separately for network equipment (MikroTik, switches, OLTs) and servers (RADIUS, billing, NMS). A rate below 80% for Critical and High patches within the required timeline is an action signal.
Detection and Response Metrics
Mean Time to Detect (MTTD) is the average time between a security event occurring and the security team becoming aware of it. For ISPs with SIEM and log monitoring, this is measured from log timestamps. Low MTTD indicates good monitoring coverage. High MTTD indicates that events are occurring and not being surfaced promptly.
Mean Time to Respond (MTTR for incidents, distinct from vulnerability MTTR) is the average time between incident detection and containment or resolution. This metric drives NOC and security team response capability improvement.
Alert false positive rate is the percentage of SIEM or security tool alerts that are investigated and found to be benign. A high false positive rate (above 80-90%) indicates that alerting thresholds or correlation rules need tuning. It also indicates a team that is alert-fatigued and at risk of missing genuine incidents embedded in noise.
Compliance Metrics
CTDISR control coverage is the percentage of the 104 controls that are implemented and evidenced, tracked as a trend. This is best managed in ComplianceIQ rather than as a manual calculation, but even a quarterly manual assessment produces the trend data needed for ISSC reporting.
Training completion rate is the percentage of staff who have completed the annual security awareness training within the required period. Anything below 95% requires follow-up before the training period closes.
Phishing simulation click rate is the percentage of simulated phishing emails that resulted in clicks or credential submission in the most recent simulation exercise. Track this as a trend: a declining rate indicates that training is improving staff resilience. A static or rising rate indicates the training content needs refreshing or targeting.
Presenting to the ISSC
Security metrics for ISSC reporting should use a format that allows non-technical board members to quickly understand status and trend: a traffic-light indicator (red, amber, green) against each metric relative to its target, the current value and the prior period value for trend context, and a brief narrative explaining any red or amber status and the planned remediation.
The CISO prepares and presents this report. For operators using CISO-as-a-Service, the ISSC reporting function includes security metrics compilation and presentation. For the underlying compliance tracking that feeds the CTDISR metrics, ComplianceIQ provides the platform data.