Browsing Panaseer's Metric catalog

  • Updated

The Metric catalog gives you a single place to explore every metric available on the Panaseer platform. You can access it from the left-hand menu bar.

From here, you can search and filter metrics by security area, type, status, or framework and click into any metric to see its attributes and related dashboards.

Panaseer's Metric Catalog

Panaseer's Metric Catalog page

A metric refers to a quantifiable measure used to monitor, evaluate, and report on the performance, status, or compliance of cybersecurity controls and processes.

Browsing the catalog

You can explore the catalog using the search bar or by browsing and filtering metrics. Searching and browsing provides a set of filters to narrow down your search. 

Click Hide categories to expand the list of metrics you can see on screen.

You can filter the list using the chips at the top of the page. Custom metrics are created by your organization by copying a core Panaseer metric and adjusting its properties.

Example Custom metrics in the catalog

Example Custom metrics in the catalog

The Panaseer chip shows all metrics that are included with the CCDs that your organization has access to. These metrics can be copied to create Custom metrics.

Example Panaseer metrics in the catalog

Example Panaseer metrics in the catalog

Click on any metric to open the metric detail page, which contains an extensive list of metric attributes and a list of dashboards that use the metric.

An example metric details page

An example metric details page

Filtering by Security area

Metrics provide data for certain categories of risk areas. For example, one set of metrics may focus on you device inventory, whilst another set may focus on the status of software patches across your infrastructure. 

Panaseer's metrics are categorized by these security areas, which you can see in the filter options on the left-hand side of the page.

Filter metrics by Security area

Filter by Security area

These security areas are also known as Cyber Control Domains, as they represent different domains in which your cybersecurity controls operate.

For a complete list of domains and their metrics, see Cyber Control Domains.

Filtering by Metric type

Panaseer includes several categories of metrics and measures to ensure you have a high quality, effective measurement program that follows data science best practice. Throughout this guide you’ll see examples of all of these, so here’s a quick introduction to what they are and the value they provide.

Filter by Metric type

Filter by Metric type

Informational measures

Informational measures are straightforward counts and sums. For example, total number of vulnerabilities, or total number of Windows 7 machines. They are the building blocks for many of our more complex measurements.

Coverage metrics

Coverage metrics provide essential context for any performance measures. It is measurement best practice to be aware of what information you cannot capture. For example, there is no information on the state of vulnerabilities on devices that have not been scanned. Therefore, we strongly recommend that for every security area you assess, you track the coverage and completeness of the data sources.

For example, the % of all eligible users who have received a phishing test (coverage metric) provides context for the % of users who failed a phishing test (policy metric). These metrics are also useful to help ensure your control tooling is deployed everywhere it should be.

Policy metrics

Policy metrics allow you to track adherence to standards across your organization. You can measure performance against your in-house standards by using Control Checks Builder, a capability of the Panaseer Platform, that enables you to tailor their value and scope as required.

You can also check your compliance against regulatory standards by configuring the scope of assets in your organization to which these apply. Policy metrics will automatically reflect these values. They are a great way to get started with CCM, by assessing how well you are currently enforcing the policies you have laid out

Diagnostic metrics

If you have identified areas of subpar performance using policy metrics, diagnostic metrics provide more in-depth insight that helps you to narrow down the root cause and quickly identify actions that help reduce risk.

Compound Risk metrics

Compound Risk metrics pull together data across multiple security domains to help identify toxic combinations of risks. Toxic combinations are when risks from different domains coexist on a particular resource.

For more information see Compound risk metrics.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.