What do ISM3 metrics measure?
Security? Risk? ISM3 metrics do not measure risk or security directly. Metrics in ISM3 are process metrics that measure: • Activity: The number of outputs produced, their mean age, the mean time between outputs submissions, mean time to produce an output, following input, and worst case time to produce an output, following input. • Scope: The proportion of the environment or system that is protected by the process and the percentage of the scope sampled. • Unavailability: The time since a process has performed as expected upon demand (uptime), the frequency and duration of interruptions. • Effectiveness: Number of inputs, mean time between inputs, and percentage of inputs that produce an output. • Efficiency: Ratio between the number of outputs submitted and the available resources for this process in actual use. • Load: Percentage of resources in actual use. • Quality: Accuracy, precision, or other measurements of fitness for purpose of the output, when applicable. Every process in IS