How CISOs can create security KPIs and KRIs
How CISOs can create security KPIs and KRIs “There’s a lack of collaboration between the two parties,” says Steve Durbin, managing director of theInformation Security Forum (ISF), a nonprofit association that researches and analyzes security and risk management issues. “What is the common language that we should be speaking? How could we, from a security standpoint, be focused on the right things from a business perspective?” Research by the ISF has found that many CISOs are reporting the wrong key performance indicators (KPIs) and key risk indicators (KRIs)....