Short answer
Useful compliance KPIs for CISOs measure readiness, operation and improvement: control coverage, evidence completeness, overdue access reviews, patching within SLA, open findings by age, corrective action closure time, training completion, supplier assessments current, incident response times, backup restore success, policy review currency and audit results. Each needs a definition, owner, source and target.
Key takeaways
- Report a small, stable set of metrics, with trends rather than snapshots.
- Each metric needs a definition, data source, owner and target.
- Leading indicators (overdue reviews) matter more than lagging ones (incidents).
- The same metrics evidence ISO 27001 clause 9.1 monitoring and measurement.
What boards actually want to know
Boards ask three questions: are we compliant enough to keep selling and stay out of trouble, are the important controls actually running, and is it getting better or worse? A short set of metrics, reported the same way every quarter, answers all three. ISO/IEC 27001 clause 9.1 asks for the same discipline: decide what to monitor and measure, how, when, and who analyses the results.
12 metrics that work
| Metric | Definition | Typical target |
|---|---|---|
| Control coverage | Applicable controls with an owner and evidence ÷ applicable controls | ≥ 95% |
| Evidence completeness | Evidence requests approved on time ÷ requests due | ≥ 90% |
| Access reviews on time | Systems reviewed in the quarter ÷ systems in scope | 100% |
| Critical patches within SLA | Critical vulnerabilities fixed within SLA ÷ found | ≥ 95% |
| Open findings by age | Audit findings open > 90 days | Trending down |
| Corrective action closure time | Median days from finding to verified closure | < 60 days |
| Training completion | Staff completed annual training ÷ staff in scope | ≥ 98% |
| Supplier assessments current | Critical suppliers assessed in last 12 months ÷ critical suppliers | 100% |
| Incident response time | Median time from detection to containment for high-severity incidents | Trending down |
| Backup restore success | Successful restore tests ÷ tests run | 100% |
| Policy review currency | Policies reviewed within their cycle ÷ policies | 100% |
| External audit result | Major and minor nonconformities at last audit | Zero major |
Targets are illustrations. Set your own with leadership, and keep definitions stable so trends mean something.
Leading versus lagging
Incidents and audit findings tell you what already went wrong. Overdue access reviews, unpatched critical vulnerabilities and expired supplier assessments tell you what is about to. Put leading indicators first on the board slide, and use lagging ones to confirm whether they worked.
Making the metrics trustworthy
- Define each metric once, with its formula and data source, and don't change it mid-year.
- Pull numbers from systems of record (ticketing, IAM, scanners), not hand-built spreadsheets.
- Name an owner who explains movements, not just reports numbers.
- Show four to eight quarters of trend, not a single value.
How this supports ISO 27001
Clause 9.1 requires you to evaluate information security performance and ISMS effectiveness, keep evidence of the results, and use them in management review (9.3). A defined KPI set with owners and sources satisfies that, and ISO/IEC 27004 gives further guidance on designing measures.
Put this into practice on QULDEX
Frequently asked questions
How many compliance KPIs should a CISO report?
Usually 8 to 12. Fewer, stable metrics with trends are more useful to a board than a long list that changes every quarter.
Does ISO 27001 require KPIs?
Clause 9.1 requires you to decide what to monitor and measure and to evaluate performance. It doesn't name specific KPIs, but a defined metric set is the usual way to meet it.