To measure a company’s ability to deal with security incidents, the group suggested that companies measure the mean time between security incidents and the mean time to recover from security incidents.
As an indicator of a company’s network security readiness, companies should measure the fraction of systems configured to approved standards, the fraction of systems patched as per corporate policy, and the fraction of systems with antivirus software, CIS stated.
Finally, companies should review their software applications for potential security issues by measuring the fraction of business applications that have had a risk assessment, the fraction with a penetration or vulnerability assessment and the fraction of application code that had a threat-model analysis or security code review prior to deployment.
http://www.securityfocus.com/brief/814?ref=rss