A security team reports 'number of awareness emails sent' as a headline ISMS metric to top management each quarter. An auditor flags this as a vanity metric. What characteristic makes it one?
- A.It is expensive to collect relative to its value
- B.It measures activity volume rather than any outcome or change in security behaviour or risk
- C.It cannot be expressed as a percentage
- D.It is reported quarterly rather than monthly
Why B is correct
A vanity metric counts effort or output that looks impressive but says nothing about effectiveness. Emails sent does not reveal whether awareness improved or phishing susceptibility fell; an outcome measure such as phishing click-through rate would be more meaningful.
Know someone studying for ISO 27001? Send them this one.