Measuring team effectiveness¶
SOC¶
Metric  | 
Definition  | 
Meaning  | 
|---|---|---|
Mean Time to   | 
Average time the SOC takes to   | 
How effective the SOC is at processing   | 
Mean Time to   | 
Average time that transpires   | 
How effective the SOC is at gathering   | 
Total cases   | 
Number of security incidents   | 
How busy the security environment is and   | 
Types of   | 
Number of incidents by type:   | 
The main types of activity managed   | 
Analyst   | 
Number of units processed per   | 
How effective analysts are at covering   | 
Case escalation   | 
Number of events that enter   | 
The effective capacity of the SOC at each   | 
SIRT¶
Metric  | 
Definition  | 
Meaning  | 
|---|---|---|
Detection   | 
Number of alerts by dept, team, site.  | 
How effective the detection solution is.   | 
Detection to   | 
The time it takes for activity   | 
How effective analysts, detection tools,   | 
Decision   | 
The time it takes to make a   | 
Decisions are made on every alert and   | 
False positive   | 
The percentage of alerts that   | 
False positives can reduce a security team’s   | 
Time to   | 
The time it takes to see a security   | 
These numbers can vary widely but over   |