This is a Security and Privacy Balanced Scorecard Report, it is one of reports that Balanced Scorecard Designer can generate for Security and Privacy scorecard. With this software you can also design your own KPIs, Balanced Scorecards and metrics.


Security and Privacy Scorecard

Report includes: 1 month(s) 49 day(s), from 05.04.2008 to 24.05.2008

  Name Start value End value Dynamic Contains
Root Security and Privacy Scorecard 48,31 % 62,65 % + 14,34 %
Financial Perspective(65,9%, -2,14%Down)
Employee perspective(57,1%, 11,57%Up)
Security compliance(62,1%, 21,47%Up)
Incident history(67,6%, 33,02%Up)
Security policy effectiveness(60,5%, 7,73%Up)

Graph for Security and Privacy Scorecard

Graph for Security and Privacy Scorecard

Data for Security and Privacy Scorecard

DatesValue
05.04.200848,31
12.04.200850,82
19.04.200855,72
26.04.200855,03
03.05.200845,92
10.05.200845,22
17.05.200843,79
24.05.200862,65

Financial Perspective

  Name Start value End value Dynamic Parent Contains
Root Financial Perspective 68,07 % 65,93 % -2,14% Security and Privacy Scorecard
Indicators
Value-at-Risk
Return on Investment
Collateral damage potential (CDP)

Graph for Financial Perspective

Graph for Financial Perspective

Data for Financial Perspective

DatesValueWeight
05.04.200868,071
12.04.200860,331
19.04.200873,81
26.04.200839,131
03.05.200832,231
10.05.200836,371
17.05.200843,71
24.05.200865,931

Value-at-Risk

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Value-at-Risk 22,425 24,89 + 2,465 % Minimize Financial Perspective
Description Quantification based on the expected frequency with which attacks seem likely to happen and the loss given event (LGE) provoked by a single attack

Graph for Value-at-Risk

Graph for Value-at-Risk

Data for Value-at-Risk

DatesWeightMinMaxValue
05.04.2008159022,425
12.04.2008159019,195
19.04.2008159029,055
26.04.2008159085,24
03.05.2008159063,225
10.05.2008159087,195
17.05.2008159047,67
24.05.2008159024,89

Return on Investment

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Return on Investment 61,52 75,84 + 14,32 % Maximize Financial Perspective
Description The financial benefit of security investment divided by the cost of the investment, multipled by 100

Graph for Return on Investment

Graph for Return on Investment

Data for Return on Investment

DatesWeightMinMaxValue
05.04.20081109061,52
12.04.20081109010,88
19.04.20081109050,24
26.04.20081109082,08
03.05.20081109012,48
10.05.20081109084,56
17.05.20081109064,8
24.05.20081109075,84

Collateral damage potential (CDP)

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Collateral damage potential (CDP) 1,191 1,833 + 0,642 Score Minimize Financial Perspective
Description The potential for a loss of physical equipment, property damage as a result of a security breach
Target description None (0), low (1), medium (2), or high (3)

Graph for Collateral damage potential (CDP)

Graph for Collateral damage potential (CDP)

Data for Collateral damage potential (CDP)

DatesWeightMinMaxValue
05.04.20081031,191
12.04.20081030,102
19.04.20081030,018
26.04.20081032,349
03.05.20081031,137
10.05.20081032,622
17.05.20081032,616
24.05.20081031,833

Employee perspective

  Name Start value End value Dynamic Parent Contains
Root Employee perspective 45,5 % 57,07 % + 11,57% Security and Privacy Scorecard
Indicators
User compliance
Employee attitude
Employee awareness
Password effectiveness *
* - Information for this metric is limited in sample report

Graph for Employee perspective

Graph for Employee perspective

Data for Employee perspective

DatesValueWeight
05.04.200845,51
12.04.200838,61
19.04.200858,631
26.04.200863,721
03.05.200847,851
10.05.200856,021
17.05.200829,021
24.05.200857,071

User compliance

  Name Start value End value Dynamic Measure units Optimization method Parent
Root User compliance 87,31 61,12 -26,19 % Maximize Employee perspective
Description The number of users compliant with each element of the security policy divided by the total number of users, multiplied by 100

Graph for User compliance

Graph for User compliance

Data for User compliance

DatesWeightMinMaxValue
05.04.200811010087,31
12.04.200811010032,05
19.04.200811010095,5
26.04.200811010093,16
03.05.200811010018,1
10.05.200811010011,26
17.05.200811010038,62
24.05.200811010061,12

Employee attitude

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Employee attitude 41,5 18,1 -23,4 % Maximize Employee perspective
Description The percentage of employees with positive attitude toward existig security practices

Graph for Employee attitude

Graph for Employee attitude

Data for Employee attitude

DatesWeightMinMaxValue
05.04.200811010041,5
12.04.200811010061,21
19.04.200811010066,43
26.04.200811010021,25
03.05.200811010092,17
10.05.200811010086,5
17.05.200811010028,09
24.05.200811010018,1

Employee awareness

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Employee awareness 44,11 74,53 + 30,42 % Maximize Employee perspective
Description The percentage of employees capable of recognizing a security problem and taking appropriate measures to eliminate it

Graph for Employee awareness

Graph for Employee awareness

Data for Employee awareness

DatesWeightMinMaxValue
05.04.200811010044,11
12.04.200811010028,18
19.04.200811010031,87
26.04.200811010062,83
03.05.200811010070,3
10.05.200811010058,24
17.05.200811010060,85
24.05.200811010074,53

Security compliance

  Name Start value End value Dynamic Parent Contains
Root Security compliance 40,63 % 62,1 % + 21,47% Security and Privacy Scorecard
Indicators
Systems Service Level
Network Service Level
Compliant Devices

Graph for Security compliance

Graph for Security compliance

Data for Security compliance

DatesValueWeight
05.04.200840,631
12.04.200843,11
19.04.200856,71
26.04.200864,631
03.05.200857,831
10.05.200826,41
17.05.200841,131
24.05.200862,11

Systems Service Level

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Systems Service Level 79,28 81,12 + 1,84 % Maximize Security compliance
Description Percentage of time that information systems services are
available

Graph for Systems Service Level

Graph for Systems Service Level

Data for Systems Service Level

DatesWeightMinMaxValue
05.04.20081109079,28
12.04.20081109058,64
19.04.20081109020,08
26.04.20081109023,2
03.05.20081109079,6
10.05.20081109062,64
17.05.20081109057,36
24.05.20081109081,12

Network Service Level

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Network Service Level 19,52 54,08 + 34,56 % Maximize Security compliance
Description Percentage of time that network services are available

Graph for Network Service Level

Graph for Network Service Level

Data for Network Service Level

DatesWeightMinMaxValue
05.04.20081109019,52
12.04.20081109027,52
19.04.20081109078,56
26.04.20081109088,8
03.05.20081109072,16
10.05.20081109016,64
17.05.20081109052,96
24.05.20081109054,08

Compliant Devices

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Compliant Devices 31,06 48,07 + 17,01 % Maximize Security compliance
Description Number of network devices that are security policy compliant, divided by the total number of devices on the network, multiplied by 100

Graph for Compliant Devices

Graph for Compliant Devices

Data for Compliant Devices

DatesWeightMinMaxValue
05.04.200811010031,06
12.04.200811010051,94
19.04.200811010074,62
26.04.200811010081,01
03.05.200811010017,92
10.05.200811010014,59
17.05.200811010019,45
24.05.200811010048,07

Incident history

  Name Start value End value Dynamic Parent Contains
Root Incident history 34,6 % 67,62 % + 33,02% Security and Privacy Scorecard
Indicators
Number of Compromises
Organizational Impact of Compromises
Unauthorized accesses
Viruses detected *
* - Information for this metric is limited in sample report

Graph for Incident history

Graph for Incident history

Data for Incident history

DatesValueWeight
05.04.200834,61
12.04.200839,651
19.04.200840,11
26.04.200864,21
03.05.200846,551
10.05.200857,421
17.05.200854,61
24.05.200867,621

Number of Compromises

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Number of Compromises 200,24 201,04 + 0,8 % Minimize Incident history
Description Number of incidents during a given period in which
network or systems security was compromised divided by industry benchmarking figures, multiplied by 100

Graph for Number of Compromises

Graph for Number of Compromises

Data for Number of Compromises

DatesWeightMinMaxValue
05.04.2008190250200,24
12.04.2008190250241,36
19.04.2008190250209,84
26.04.200819025090,64
03.05.2008190250102,32
10.05.2008190250176,24
17.05.2008190250131,28
24.05.2008190250201,04

Organizational Impact of Compromises

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Organizational Impact of Compromises 1,032 0,939 -0,093 % Minimize Incident history
Description For each incident, the number of hours, time of day, and people affected by the degradation or disruption of network, systems or application services
Target description None (0), low (1), medium (2), or high (3)

Graph for Organizational Impact of Compromises

Graph for Organizational Impact of Compromises

Data for Organizational Impact of Compromises

DatesWeightMinMaxValue
05.04.20081031,032
12.04.20081031,464
19.04.20081032,082
26.04.20081031,17
03.05.20081032,142
10.05.20081030,99
17.05.20081031,638
24.05.20081030,939

Unauthorized accesses

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Unauthorized accesses 45,394 9,439 -35,96 % Minimize Incident history
Description Number of unauthorized access attempts for various
network services (VPN, HTTP, SSH, etc) divided by the total number of access attempts, multiplied by 100

Graph for Unauthorized accesses

Graph for Unauthorized accesses

Data for Unauthorized accesses

DatesWeightMinMaxValue
05.04.2008135045,394
12.04.2008135023,774
19.04.2008135025,325
26.04.2008135021,941
03.05.2008135028,098
10.05.2008135018,886
17.05.2008135037,78
24.05.200813509,439

Security policy effectiveness

  Name Start value End value Dynamic Parent Contains
Root Security policy effectiveness 52,77 % 60,5 % + 7,73% Security and Privacy Scorecard
Indicators
Vulnerability Counts
Incident Forensics
Remediation Time

Graph for Security policy effectiveness

Graph for Security policy effectiveness

Data for Security policy effectiveness

DatesValueWeight
05.04.200852,771
12.04.200872,431
19.04.200849,41
26.04.200843,431
03.05.200845,131
10.05.200849,91
17.05.200850,51
24.05.200860,51

Vulnerability Counts

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Vulnerability Counts 36,32 38,525 + 2,205 % Minimize Security policy effectiveness
Description The number of vulnerabilities found on policy compliant devices divided by the number of vulnerabilities found on policy non-compliant devices

Graph for Vulnerability Counts

Graph for Vulnerability Counts

Data for Vulnerability Counts

DatesWeightMinMaxValue
05.04.2008155036,32
12.04.2008155018,86
19.04.2008155034,475
26.04.2008155019,175
03.05.200815507,655
10.05.2008155014,405
17.05.2008155027,32
24.05.2008155038,525

Incident Forensics

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Incident Forensics 10,13 10,51 + 0,38 % Minimize Security policy effectiveness
Description The number of incidents attributable to policy failures divided by the number of policy compliance failures

Graph for Incident Forensics

Graph for Incident Forensics

Data for Incident Forensics

DatesWeightMinMaxValue
05.04.20081510010,13
12.04.20081510011,27
19.04.20081510045,85
26.04.20081510086,985
03.05.20081510082,425
10.05.20081510040,055
17.05.20081510076,155
24.05.20081510010,51

Remediation Time

  Name Start value End value Dynamic Measure units Optimization method Parent
Root Remediation Time 2,001 1,146 -0,855 % Minimize Security policy effectiveness
Description Time between compromise discovery and completion of system remediation
Target description None (0), low (1), medium (2), or high (3)

Graph for Remediation Time

Graph for Remediation Time

Data for Remediation Time

DatesWeightMinMaxValue
05.04.20081032,001
12.04.20081031,359
19.04.20081031,299
26.04.20081031,557
03.05.20081032,316
10.05.20081032,775
17.05.20081030,72
24.05.20081031,146
Created by: AKS-Labs
Report created with Balanced Scorecard Designer at 28.04.2008 23:59:05

Copyright © 2000-2008 AKS-Labs. All rights reserved.