Goals, Questions, Metrics
This week we take a short trip back into the world of data science to introduce a framework we’ve adopted to support the delivery of Security Insights to our customers. Goals, Questions, Metrics (GQM) is a measurement model that uses business level objectives (in our case the pursuit of better security) to drive the identification of the right metrics to help organisations to measure progress against those objectives.I came across the GQM framework after a presentation by Alex Hutton and David Mortman at RSA last year and doing some further research into the subject I was struck by its simplicity and effectiveness:
- Goals: The definition of what we want to accomplish
- Questions: Contextualise the goal and help to understand how they can be achieved
- Metrics: The quantitative measurement that helps to answer the question
- Goal: Comprehensive coverage of vulnerability scanning.
- Question: What proportion of the estate is currently scanned by the vulnerability scanner?
- Metric: Percentage of estate scanned