Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

How to Build a Cybersecurity Metric Data Dictionary That Executives Can Actually Trust

Cybersecurity Metric Data Dictionary: Make Every Dashboard Number Reproducible Audience: security program managers, GRC leads, control owners, audit coordinators, and consultants A dashboard can look precise while hiding a basic operating problem: two people cannot reproduce the same number from the same evidence. The usual cause is not a charting tool. It is an undefined metric contract—scope,…

Creating a Trustworthy Cybersecurity Metric Data Dictionary for Executive Use

Aim: The goal is to develop a data dictionary that ensures every cybersecurity dashboard number is reproducible and trustworthy for executives. The issue is that multiple people may not be able to reproduce the same number from the same evidence due to undefined metric contracts.

NIST Guidance: The National Institute of Standards and Technology (NIST) provides a measurement program framework for collecting, analyzing, and communicating data used to monitor information security risk. NIST recommends documenting scope, numeric measure, formula, target, implementation evidence, responsible parties, data source, time reference, and reporting format.

The Problem: A common issue with dashboards is that they may appear precise but hide a basic operational problem. The problem lies in undefined metric contracts, which include scope, formula, denominator, source, timestamp, owner, validation, and exception handling.

A Solution: A practical data dictionary should turn those ideas into one reviewable record per metric. It should include boundary information, such as being an operational design guide and not legal advice, audit opinion, certification, or evidence of control effectiveness.

Key Points:

- Define a stable metric ID and capture necessary fields before a metric enters a recurring report

- Include fields like Metric ID, decision question, scope, grain, numerator, denominator, formula, target, source system, as-of rule, freshness SLA, validation schema, and exception policy

- Ensure clear definition of terms like metric ID, decision question, scope, grain, numerator, denominator, formula, target, source system, as-of rule, freshness SLA, validation schema, and exception policy

- Follow a four-step quality gate process before publishing the metric, which includes definition gate, data gate, reproduction gate, and communication gate

Implementation: To build a trustworthy cybersecurity metric data dictionary, security program managers, GRC leads, control owners, audit coordinators, and consultants should work together to implement these guidelines. By following this data dictionary, executives can trust the numbers presented on cybersecurity dashboards and make informed decisions based on accurate and reliable data.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

I couldn't find a tool that lets agents verify what they're buying. So I built it.

I built ScrapeCheck because as someone who has been in the crypto industry for over 9 years, I know how important it is for information to be public, like the blockchain.

  • Fieldmode LLC creates ScrapeCheck tool for agent data verification
  • Tool independently fetches webpages, compares to agent-provided data
  • ScrapeCheck marks unverifiable data with "unverifiable" verdict

Migrating Off Nordigen: A Field Guide for Indie Builders (2026)

What happened The short version: the era of free bank data for side projects is over at the big aggregators. Nordigen — the Latvian open-banking startup that ran a genuinely free account-information…

  • GoCardless acquires Nordigen, ending free API tier for indie developers
  • Three migration paths: direct PSD2 integration, aggregator-based solutions, full broker aggregator
  • 90-day re-authentication window required for each migration

Going Dark: Why Law Enforcement Hacking Is the New Surveillance Frontier

Going Dark: Why Law Enforcement Hacking Is the New Surveillance Frontier A provocative essay by cryptography engineer Matthew Green titled "Going Dark, and the era of law enforcement hacking" reached…

  • Essay "Going Dark" fuels debate on law enforcement hacking as new surveillance frontier.
  • Encryption debate resolved through hacking endpoints like phones, laptops, tablets.
  • Policy gap exists for government hacking with no legal framework or data handling rules.

How to Handle Audio Transcription API 404/501 — available=false Speech-to-Text in 2026

Short answer: route production supplier-invoice audio to an external speech-to-text provider whenever the model catalog does not advertise an available ASR model, and record that routing decision…

  • 404, 501, or available=false status indicates unavailable ASR model
  • External speech-to-text provider recommended for production invoices
  • System implements ASR port with catalog check and tenant usage ledger

More from Saturday 15 August →