|
+Key Risk Indicators (KRIs) |
Key Risk Indicators (KRIs)DescriptionMechanisms exist to develop, report and monitor Key Risk Indicators (KRIs) to assist senior management in performance monitoring and trend analysis of the Security, Compliance & Resilience Program (SCRP).Possible Solutions & ConsiderationsMicro-Small Business (<10 staff) / BLS Firm Size Classes 1-2∙ Manually-generated metrics (spreadsheet)∙ Basic risk indicators: critical unpatched vulnerabilities, failed logins, open security incidents Small Business (10-49 staff) / BLS Firm Size Classes 3-4∙ Manually-generated KRI tracking with alert thresholds∙ GRC solution (e.g., SCFConnect, Cyturus, SureCloud, SimpleRisk, Ignyte, ZenGRC, Galvanize, MetricStream, Archer, etc.) ∙ Documented risk tolerance thresholds Medium Business (50-249 staff) / BLS Firm Size Classes 5-6∙ Defined KRI library tied to organizational risk register∙ Automated KRI monitoring via GRC platform or SIEM (e.g., Splunk, Microsoft Sentinel) ∙ GRC solution (e.g., SCFConnect, Cyturus, SureCloud, SimpleRisk, Ignyte, ZenGRC, Galvanize, MetricStream, Archer, etc.) Large Business (250-999 staff) / BLS Firm Size Classes 7-8∙ Formal KRI program with defined risk appetite thresholds∙ Automated KRI monitoring with escalation triggers ∙ GRC platform with KRI dashboards linked to risk register ∙ Regular KRI reporting to risk committee Enterprise (> 1,000 staff) / BLS Firm Size Class 9∙ Enterprise KRI program integrated with risk management framework∙ Automated real-time KRI monitoring with AI-assisted anomaly detection ∙ Board-level risk indicator reporting with trend analysis ∙ KRIs linked to enterprise risk appetite and materiality thresholds SCR-CMMLevel 0 Not PerformedPractices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.Level 1 Performed InformallyCybersecurity & Data Protection Governance (GOV) domain capabilities are ad hoc and inconsistent. Capability criteria associated with this control may include:▪ Policies, standards & procedures associated with GOV domain capabilities provide limited coverage due to the depth and breadth of the existing documentation. ▪ Governance-related activities are decentralized (e.g., a localized/regionalized function) and uses non-standardized methods to implement secure, resilient and compliant practices. ▪ No formal Governance, Risk & Compliance (GRC) team exists. GRC roles are assigned to existing IT/cybersecurity personnel. ▪ Cybersecurity and data protection governance is informally assigned as an additional duty to existing IT/cybersecurity personnel. ▪ Organizational leadership maintains an informal process to review and respond to observed trends. Level 2 Planned TrackedSCR-CMM Level 2 criteria definitions are not available for this control:▪ A reasonable person would conclude a well-defined and standardized process is required. ▪ At this level of maturity, the “requirements-driven” nature of performing the control is focused on a localized and/or regionalized implementation, not uniform and consistent across the organization. ▪ Requirements are narrowly scoped for applicability and are primarily derived from compliance obligations (e.g., laws, regulations and contracts). Level 3 Well DefinedCybersecurity & Data Protection Governance (GOV) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function. ▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are well-documented and kept current by process owners. ▪ The entity's GRC team, or similar function, is appropriately staffed and supported to implement and maintain GOV domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls). ▪ Technology is leveraged to enhance the efficiency and accuracy of governance, risk management and compliance operations (e.g., GRC platform). ▪ An implemented and operational capability exists to develop, report and monitor Key Risk Indicators (KRIs) to assist senior management in performance monitoring and trend analysis of the Security, Compliance & Resilience Program (SCRP). Level 4 Quantitatively ControlledCybersecurity & Data Protection Governance (GOV) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational. ▪ Metrics reporting includes quantitative analysis of Key Performance Indicators (KPIs). ▪ Metrics reporting includes quantitative analysis of Key Risk Indicators (KRIs). ▪ Scope of metrics, KPIs and KRIs covers organization-wide cybersecurity and data protection controls, including functions performed by third-parties. ▪ Organizational leadership maintains a formal process to objectively review and respond to metrics, KPIs and KRIs (e.g., monthly or quarterly review). ▪ Based on metrics analysis, process improvement recommendations are submitted for review and are handled in accordance with change control processes. ▪ Business and technical stakeholders are involved in reviewing and approving proposed changes to evolve capabilities. Level 5 Continuously ImprovingCybersecurity & Data Protection Governance (GOV) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational. ▪ Based on predictive analysis, process improvements are implemented according to “continuous improvement” practices that affect process changes. ▪ Stakeholders make time-sensitive decisions to support operational efficiency, which may include automated remediation actions. 1. Übersicht
1.1 Referenzen1.2 Identifizierte Anforderungen1.3 Related Regulations2. Identifizierte Anforderungen
3. Related Regulations
Linked Issues
|