Understand how teams and tools are performing. Demonstrate progress for executive stakeholder reporting.
There are hundreds of security controls, as defined by common security frameworks by organizations such as the National Institute of Standards and Technology (NIST) and the Center for Internet Security (CIS). Implementing these security controls, processes and procedures is a common practice by almost any organization in order to provide reasonable assurance that business objectives will be achieved and undesired events will be detected, corrected, and prevented. However, identifying gaps in security controls and reporting progress can be difficult, if not almost impossible.