An organization is implementing security metrics. Which characteristic is MOST important for a metric to be useful for security management decisions?
-
A
The metric should be technically complex to demonstrate program sophistication
-
B
The metric should be actionable and tied to a specific decision or outcome
-
C
The metric should track the largest possible volume of security events
-
D
The metric should be self-reported by the team being measured