# What are Security Metrics?

> Security metrics are the measurements used to describe control coverage, detection performance, exposure, and program effectiveness over time.

- Canonical URL: https://yellowcube.eu/glossary/security-metrics/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Useful metrics connect a defined measurement to a decision: patch latency, detection coverage, mean time to detect and respond, control test results, exception counts, and exposure trends. Weak metrics count activity — tickets closed, alerts processed — without showing whether risk changed.

### Key points

- **Precise definitions:** Name the data source, population, time window, owner, and the decision the number informs.
- **Outcomes over activity:** Measure coverage, correctness, and timeliness rather than volume of work performed.
- **Important limitation:** Metrics are models of security, not proof of it. Goodhart’s law applies — once a number becomes a target, teams optimize the number instead of the protection it was meant to represent.

### Related terms

[Mean time to detect (MTTD)](<https://yellowcube.eu/glossary/mean-time-to-detect/>) · [Mean time to respond (MTTR)](<https://yellowcube.eu/glossary/mean-time-to-respond/>) · [Security operations (SecOps)](<https://yellowcube.eu/glossary/security-operations/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>)

### Sources

[NIST SP 800-55 Rev. 2, Performance Measurement Guide for Information Security](https://csrc.nist.gov/pubs/sp/800/55/v2/final) · [NIST IR 8286r1, Integrating Cybersecurity and Enterprise Risk Management](https://csrc.nist.gov/pubs/ir/8286/r1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

