TVM-10: Vulnerability Management Metrics

Control Statement

Establish, monitor and report metrics for vulnerability identification and remediation at defined intervals.

Implementation Guidance

The integrated TVM system should be used to collect and report metrics about the vulnerability management program. Metrics should demonstrate the coverage, efficacy, and efficiency of operational TVM activities.

Auditing Guidance

  1. Verify that metrics have been established to measure vulnerabilities.
  2. Examine the process for reporting metrics, including identification of recipients.
  3. Determine if reports are sent at the defined intervals.

