Measuring team effectiveness¶
SOC¶
Metric |
Definition |
Meaning |
---|---|---|
Mean Time to |
Average time the SOC takes to |
How effective the SOC is at processing |
Mean Time to |
Average time that transpires |
How effective the SOC is at gathering |
Total cases |
Number of security incidents |
How busy the security environment is and |
Types of |
Number of incidents by type: |
The main types of activity managed |
Analyst |
Number of units processed per |
How effective analysts are at covering |
Case escalation |
Number of events that enter |
The effective capacity of the SOC at each |
SIRT¶
Metric |
Definition |
Meaning |
---|---|---|
Detection |
Number of alerts by dept, team, site. |
How effective the detection solution is. |
Detection to |
The time it takes for activity |
How effective analysts, detection tools, |
Decision |
The time it takes to make a |
Decisions are made on every alert and |
False positive |
The percentage of alerts that |
False positives can reduce a security team’s |
Time to |
The time it takes to see a security |
These numbers can vary widely but over |