SOC analysts compile rich security process metrics that never leave the operations drawer. What is required for those metrics to fulfill their assessment purpose?
Select an answer to reveal the explanation.
Short Explanation
Metrics trapped in a SOC drawer are like unread lab results—useful only when a doctor acts. Push them into management review. Hiding them, dumping pcaps online, or swapping posters for data skips that step.
Full Explanation
Security process data supports governance only when management reviews and acts on it. Isolation inside operations, inappropriate public dumps of technical telemetry, or substituting slogans for evidence prevents informed approval of risk decisions. Municipal leadership needs a deliberate review path for assessment-derived metrics.