MedISA Logo

MedISA

Medical Centre Employee Centered Information Security Awareness


Key Performance Indicators for Measuring Objective Information Security Awareness

These metrics make human behavior and the knowledge level of staff members quantifiable. They make it possible to systematically evaluate the effectiveness of training, awareness campaigns, or internal policies and to continuously improve them based on that data. The collection and interpretation of such KPIs should take place within the framework of appropriate observational designs in order to produce meaningful and reliable results. The KPIs considered in the project do not represent a complete list, but rather offer exemplary reference points for data-driven evaluation of security-relevant measures.

KPIExplanationLevel
Password complexity (length)Strength of passwords chosen for access protectionPer user
Password change intervalFrequency of password changes to avoid long-term compromisePer user
Number of reported security incidentsNumber of registered security incidentsEntire clinic or organizational units
IT security training rate in the clinicProportion of employees who have received trainingPer user
Security incidents involving human errorIncidents in which human failure played a rolePer user
Awareness of reporting procedureEmployee awareness of the process for reporting incidentsPer user
Click rates in phishing campaignsProportion of clicks on simulated phishing emailsPer user
Clean deskImplementation of tidy workspaces for data protectionPer user
Rate of accounts locked due to incorrect password entryUser accounts locked due to repeated incorrect login attemptsPer user
Number of security incidentsAbsolute number of security-related incidentsEntire clinic or organizational units