Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Vulnerability Management Metrics Workbook

Produces the four metrics that survive management scrutiny — coverage, mean time to remediate by severity, SLA adherence and overdue exposure — from the tracker data.

Available soon

Format
Excel
Size
213 KB
Length
12 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Tracker Data
  • Coverage Data
  • Metric Definitions
  • Metrics
  • Trend
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Tracker Data sheet: in the Vulnerability Remediation Tracker, copy the whole tracker table's data rows (sheet Tracker, columns A to AE, from row 4 down). Paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order, headings on row 3: Example | Finding ID | Asset ID | Asset name | Internet-facing | Asset criticality | Vulnerability reference | Title | Scanner severity | Exploited | Suggested priority | Priority | Priority change reason | Detected date | Deadline | Mitigation due (Priority 1) | Mitigation applied date | Owner | Ticket reference | Status | Exception ID | Exception expiry | Closure evidence | Verified closed date | Days open | Days to deadline | Days past deadline | Deadline status | Escalation | Record check | Notes.
2Do not paste over the grey calculated columns to the right of column AE. If the export has more rows than the table, drag the table's bottom-right corner down first so the calculated columns extend.
3Dates must be real dates, not text. After pasting, check that the Detected date, Deadline, Exception expiry and Verified closed date columns are right-aligned; left-aligned dates are text and will not be counted.
4Coverage Data sheet: add one row per scanning period from the Scan Coverage & Asset Scope Register — the period, the In-scope systems and Scanned within required frequency figures from its Summary sheet — and, from the scanner's login report, the authenticated scan attempts and successes.
5Metrics sheet: enter the period start and end dates, and how many months each period covers (1 for monthly reporting, 3 for quarterly). The previous period is worked out for you.
6Check the targets on the Metrics sheet. The deadlines per priority come from the Standard; the deadline adherence target is yours to agree with the approver.
7Read the results. Every figure has a status in words beside it; the colour only repeats what the word says. 'No closures' or 'No data' means there was nothing to measure, which is not the same as zero.
8Write the commentary: what changed, why, and what you need from management. Record whether the latest Vulnerability Scanner Configuration Review Checklist said the figures are ready to report upward.
9Trend sheet: shows the same measures for the twelve periods ending with the chosen one. Use it to show direction; one period on its own rarely tells management much.
10Printing: the Tracker Data sheet prints only its first 25 rows, so that empty input rows do not print as blank pages. To print all your data, clear or reset the print area on that sheet (Page Layout → Print Area).
11Delete the EXAMPLE rows on the Tracker Data and Coverage Data sheets before you paste your own data, then check the Metrics sheet recalculates.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Columns used in calculations: Finding ID, Priority (the number 1 to 4), Detected date, Deadline, Status, Exception ID, Exception expiry and Verified closed date. The tracker's own day counts and Deadline status are carried across but not used, because they are calculated against today's date rather than the period you chose. If you change the tracker's columns, change this sheet's to match.

Priority is read from the digit 1 to 4 in the Priority column, so '2', 'P2' and 'Priority 2 — High' all work.

A finding counts as closed on its Verified closed date — the date a later scan (or other objective evidence) confirmed the fix (VM-13). A finding with Status 'Closed — false positive' is left out of every metric. 'Closed — system retired' counts as remediated on its Verified closed date.

A finding past its deadline is not counted as overdue while it has an Exception ID and an Exception expiry on or after the period end (VM-16, VM-17). An exception with no expiry date does not protect a finding.

Tailoring — small organisation: report quarterly (enter 3 months per period) if you close only a handful of findings a month; averages of two or three findings swing wildly. Keep Priority 1 overdue exposure monthly regardless.

Tailoring — regulated financial entity: report to the management body at least quarterly (VM-20), keep each period's copy of this workbook as a record, and add the scanner review result to every report. Supervisors ask how figures were produced as well as what they are.

Tailoring — IT run by a service provider: ask the provider for the tracker export in the column order above, calculate the figures yourself, and compare them with the provider's own service report. Use the deadlines in your agreement with them if they differ from the Standard.

Tracker Data

Paste the whole Vulnerability Remediation Tracker table here as values (columns A–AE, from row 4). Columns AF–AI are calculated. The five EXAMPLE rows show the format — delete them first.

ExampleFinding IDAsset IDAsset nameInternet-facingAsset criticalityVulnerability referenceTitleScanner severityExploitedSuggested priorityPriorityPriority change reasonDetected dateDeadlineMitigation due (Priority 1)Mitigation applied dateOwnerTicket referenceStatusException IDException expiryClosure evidenceVerified closed dateDays openDays to deadlineDays past deadlineDeadline statusEscalationRecord checkNotesPriority level (calc)Counted (calc)Days to verified closure (calc)Closed within deadline (calc)
EXAMPLEVUL-0001SRV-014Customer portal web serverYesCriticalCVE-2026-10001Remote code execution in web server moduleCriticalYes116 Jul 202613 Jul 20269 Jul 20267 Jul 2026IT Operations ManagerCHG-2291Closed — verified fixedRescan 2026-07-10 clean10 Jul 2026Closed on time1Yes4Yes
EXAMPLEVUL-0002SRV-031File serverNoHighCVE-2026-10002Privilege escalation in operating systemHighNo3322 Jun 202622 Jul 2026IT Operations ManagerINC-4410Closed — verified fixedRescan 2026-07-29 clean29 Jul 2026Closed late3Yes37No
EXAMPLEVUL-0003FW-002Perimeter firewallYesCriticalCVE-2026-10003Authentication bypass in management interfaceHighNo223 Aug 202617 Aug 2026Network EngineerCHG-2340Closed — verified fixedRescan 2026-08-14 clean14 Aug 2026Closed on time2Yes11Yes
EXAMPLEVUL-0004SRV-022Remote access gatewayYesHighCVE-2026-10004Information disclosure in remote access serviceHighNo224 Aug 202618 Aug 2026IT Operations ManagerINC-4502In progressOverdueAsset owner's manager2Yes
EXAMPLEVUL-0005APP-007Finance application serverNoCriticalCVE-2026-10005Outdated database driverHighNo3313 Jul 202612 Aug 2026Finance Systems LeadCHG-2318OpenEXC-2026-00431 Oct 2026Exception3Yes

Coverage Data

One row per scanning period, from the Scan Coverage & Asset Scope Register. A row counts towards a reporting period when its dates fall inside it.

Row typePeriod startPeriod endIn-scope systemsScanned within required frequencyAuthenticated scans attemptedAuthenticated scans that logged inSourceScan coverage (calc)Coverage status (calc)Authenticated success (calc)
EXAMPLE1 Apr 202630 Apr 2026180162150132Coverage register Summary, April export90.0%Below target88.0%
EXAMPLE1 May 202631 May 2026182168152141Coverage register Summary, May export92.3%Below target92.8%
EXAMPLE1 Jun 202630 Jun 2026185175154146Coverage register Summary, June export94.6%Below target94.8%
EXAMPLE1 Jul 202631 Jul 2026186178155148Coverage register Summary, July export95.7%Met95.5%
EXAMPLE1 Aug 202631 Aug 2026190184158152Coverage register Summary, August export96.8%Met96.2%

Metric Definitions

Metric definitions

The four headline measures, defined once so that every report calculates them the same way (Standard requirement VM-21). Change a definition only through a new version of the Vulnerability & Exposure Management Standard.

MeasureDefinitionHow this workbook calculates itTargetHow to read it
Scan coverageIn-scope systems successfully scanned in the period ÷ in-scope systems.Sum of 'Scanned within required frequency' ÷ sum of 'In-scope systems' for the Coverage Data rows whose dates fall inside the period.≥ 95% (VM-02)Every other figure is only as good as this one. A drop in open findings with a drop in coverage is not an improvement.
Mean time to remediate, by priorityAverage calendar days from first detection to verified closure, for findings closed in the period. Shown per priority rather than per scanner severity, because the Standard sets its deadlines per priority.Average of (Verified closed date − Detected date) for counted findings with a Verified closed date inside the period, for each priority 1 to 4.Below each priority's deadline: P1 7 days, P2 14 days, P3 30 days, P4 90 days.An average above the deadline means the typical finding is late, not just a few. A small number of closures makes the average unreliable — look at the count.
Deadline adherenceFindings closed in the period within their deadline ÷ findings closed in the period. Deadlines are those set per priority in the Standard (sometimes called the SLA, service level agreement).Findings with a Verified closed date inside the period and on or before their Deadline ÷ all findings with a Verified closed date inside the period.[[Target, e.g. ≥ 90%]]Shows whether the deadlines the business agreed are being kept. It counts only closed findings; overdue exposure shows the ones still open.
Overdue exposureOpen findings past their deadline with no approved exception, by priority, with the age of the oldest.Findings detected by the period end, not closed by it, with a Deadline before the period end and no exception still in force at the period end. Oldest = period end − Deadline, in days.Zero Priority 1; trend down for the restThe measure that most often needs a management decision: more people, an accepted risk, or a system retired. Any Priority 1 here needs action now.

Supporting measures (also required by VM-20)

MeasureDefinitionHow this workbook calculates itTargetHow to read it
Authenticated scan successAuthenticated scans that logged in successfully ÷ authenticated scans attempted, in the period.Sum of the two authenticated columns on Coverage Data for rows inside the period.≥ 95% (VM-05)A failed login produces a scan that looks clean. Low success makes coverage and open-finding counts optimistic.
Open findings at period endCounted findings detected by the period end and not closed by it, by priority.As overdue exposure, without the deadline and exception tests.No target — contextThe workload behind the other figures.
Active exceptions at period endOpen findings with an exception still in force at the period end.Exception ID present and Exception expiry on or after the period end.No target — contextRising exceptions can hide falling adherence. Each one has a named risk owner (VM-17).

Metrics

Metrics for the period

Yellow cells are yours: the period, the targets and the commentary. Everything else is calculated. Each figure has a status in words; the colour only repeats it.

Reporting period

SettingValue
Period start1 Aug 2026EXAMPLE period — replace with your own
Period end31 Aug 2026
Months in each period (1 = monthly, 3 = quarterly)1
Previous period start1 Jul 2026
Previous period end31 Jul 2026

Targets

TargetValue
Scan coverage (VM-02)95%
Deadline adherence — agree with the approver90%[[Confirm the adherence target — 90% is a suggestion]]
Authenticated scan success (VM-05)95%
Priority 1 — Emergency — deadline in days7Deadlines from the Standard, section 5.2. Change them only if the Standard changes.
Priority 2 — High — deadline in days14
Priority 3 — Medium — deadline in days30
Priority 4 — Low — deadline in days90

This period against the previous period

MeasureTargetThis periodPrevious periodChangeStatusCommentary — what changed and why
Scan coverage≥ 95%96.8%95.7%+1.1%Met
Mean time to remediate — Priority 1 — Emergency (days)≤ 7 daysNo closures4.0—No closures
Mean time to remediate — Priority 2 — High (days)≤ 14 days11.0No closures—Within deadline
Mean time to remediate — Priority 3 — Medium (days)≤ 30 daysNo closures37.0—No closures
Mean time to remediate — Priority 4 — Low (days)≤ 90 daysNo closuresNo closures—No closures
Deadline adherence≥ 90%100.0%50.0%+50.0%Met
Findings closed in the period—12-1
of which closed within deadline—110
Overdue exposure — all prioritiesFalling10+1Rising
Overdue exposure — Priority 1 — EmergencyZero000Met
Overdue exposure — Priority 2 — HighFalling10+1Rising
Overdue exposure — Priority 3 — MediumFalling000No change
Overdue exposure — Priority 4 — LowFalling000No change
Oldest overdue finding (days past deadline)—130+13
Authenticated scan success≥ 95%96.2%95.5%+0.7%Met
Open findings at period end — Priority 1 — Emergency—000
Open findings at period end — Priority 2 — High—10+1
Open findings at period end — Priority 3 — Medium—110
Open findings at period end — Priority 4 — Low—000
Active exceptions at period end—110

Change is this period minus the previous one; for percentages it is in percentage points. 'Rising' overdue exposure is the direction to act on even when the number is small.

Commentary for management

QuestionAnswer
The headline in one sentence[[e.g. Coverage is above target for the second month; one Priority 2 finding on the remote access gateway is overdue.]]
Decisions or support needed from management[[e.g. Approve a maintenance window for the remote access gateway, or accept the risk until it is replaced.]]
Limits on these figures[[e.g. Authenticated scanning failed on 18 servers in August, so open findings on those servers are under-counted.]]

Latest Vulnerability Scanner Configuration Review Checklist — ready to report upward?

Date of that review

Prepared by (name, role) and date[[Name, role, YYYY-MM-DD]]

Trend

Trend — twelve periods to the chosen period end

The same measures for the twelve periods ending with the period chosen on the Metrics sheet. 'No data' and 'No closures' mean there was nothing to measure in that period. Use the last column to note what happened.

Period startPeriod endScan coverageCoverage statusMTTR P1 (days)MTTR P2 (days)MTTR P3 (days)MTTR P4 (days)MTTR statusFindings closedDeadline adherenceAdherence statusOverdue — allOverdue — P1Oldest overdue (days)Overdue statusCommentary
Target95.0%≤ 7≤ 14≤ 30≤ 9090.0%Falling0
1 Sep 202530 Sep 2025No dataNo data————No closures0No closuresNo closures000—
1 Oct 202531 Oct 2025No dataNo data————No closures0No closuresNo closures000No change
1 Nov 202530 Nov 2025No dataNo data————No closures0No closuresNo closures000No change
1 Dec 202531 Dec 2025No dataNo data————No closures0No closuresNo closures000No change
1 Jan 202631 Jan 2026No dataNo data————No closures0No closuresNo closures000No change
1 Feb 202628 Feb 2026No dataNo data————No closures0No closuresNo closures000No change
1 Mar 202631 Mar 2026No dataNo data————No closures0No closuresNo closures000No change
1 Apr 202630 Apr 202690.0%Below target————No closures0No closuresNo closures000No change
1 May 202631 May 202692.3%Below target————No closures0No closuresNo closures000No change
1 Jun 202630 Jun 202694.6%Below target————No closures0No closuresNo closures000No change
1 Jul 202631 Jul 202695.7%Met4.0—37.0—Above deadline250.0%Below target000No change
1 Aug 202631 Aug 202696.8%Met—11.0——Within deadline1100.0%Met1013Rising

MTTR = mean time to remediate: average calendar days from first detection to verified closure, for findings closed in the period. Overdue figures are counted at each period's end. No score is combined from these measures; read each one against its own target.

Lists

PriorityLevelStatusDeadlineStatusYesNoCriticalitySeverityReviewResult
1OpenOn trackYesCriticalCriticalReady
2In progressDue soonNoHighHighReady, with limitations
3Awaiting verificationOverdueStandardMediumNot ready
4Closed — verified fixedExceptionLowNot reviewed in the last 6 months
Closed — false positiveClosed on time
Closed — system retiredClosed late

Definitions

Definitions

TermMeaning in this workbook
Counted findingA finding whose Status does not contain 'false positive' or 'duplicate'. Only counted findings enter the metrics.
DeadlineThe date by which a finding must be fixed: detection date plus the days for its priority in the Vulnerability & Exposure Management Standard (VM-08).
Deadline adherenceOf the findings closed in the period, the share closed on or before their deadline. Sometimes called SLA (service level agreement) adherence.
ExceptionAn approved, time-limited decision not to fix a finding by its deadline, with a named risk owner and an expiry date (VM-16, VM-17).
In force (exception)An exception whose expiry date is on or after the period end.
Mean time to remediate (MTTR)Average calendar days from first detection to verified closure, for findings closed in the period, shown per priority.
Overdue exposureOpen findings past their deadline with no exception in force, counted at the period end, by priority, with the age of the oldest.
PeriodThe reporting window chosen on the Metrics sheet: its start and end dates, inclusive.
PriorityThe urgency set for a finding, 1 (Emergency) to 4 (Low), from whether it is exploited, whether the system is internet-facing and its severity — see the Vulnerability Risk Rating & SLA Model.
Scan coverageIn-scope systems successfully scanned in the period ÷ in-scope systems (VM-02).
Verified closed dateThe date a later scan, or other objective evidence, confirmed the fix (VM-13). A ticket marked done is not enough.
(calc)A column or cell calculated by the workbook. Do not type or paste over it.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationWhole workbook
ISO/IEC 27001:2022Annex A 8.8 — Management of technical vulnerabilitiesMetrics, Trend
NIST CSF 2.0ID.IM-01 — “Improvements are identified from evaluations”Trend, commentary
NIST CSF 2.0GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”Metrics, period comparison
NIS2 — Directive (EU) 2022/2555Article 21(2)(f) — “policies and procedures to assess the effectiveness of cybersecurity risk-management measures”Whole workbook
DORA — Regulation (EU) 2022/2554Article 9 — protection and prevention, including documented policies for patches and updates (Article 9(4)(f))Metrics, commentary
DORA — Delegated Regulation (EU) 2024/1774Article 10 — vulnerability and patch management, including automated vulnerability scanning at least weekly for ICT assets supporting critical or important functionsOverdue exposure, remediation measures

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); PCI DSS v4.0.1