Security Effectiveness & Performance Metrics
Scope & Objectives
In alignment with Clause 9.1 and our risk-based approach, this page tracks macro-level process effectiveness rather than individual control KPIs. These metrics are dynamically reviewed alongside our Risk Register and Issues and Risk Logging to drive continuous improvement.
- Availability
- Patching Performance
- Reports to Authorities
- Report to Clients
In most cases, myDRE remained available and operational, with only one or a few core functions temporarily affected while all other functionality continued to work as expected. See for the details: SLA Performance
- 3-Month Average
- Monthly Unavailability
- Data Breaches
- Security Incidents
As part of our Early Warning Obligation automated Microsoft Azure risk alerts—including potential false positives caused by users in their VMs will be reported to their organisations (A.05.26 - Response to information security incidents and N.1.22 - Reporting incidents to external parties). We are committed to respond within 2 hours after received notification.