> For the complete documentation index, see [llms.txt](https://docs.inopli.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.inopli.com/response/dashboards/executive-dashboard.md).

# Executive Dashboard

This dashboard, <mark style="color:green;">accessible to MSS or company type users</mark>, offers detailed <mark style="color:green;">indicators on system health and alert processing</mark>, with the ability to filter by date ranges. It provides a comprehensive overview of the main aspects of security and operational efficiency.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FL7BTvSOYeEGOg0M6cTDz%2FScreenshot%202023-12-26%20at%2019.15.40.png?alt=media&amp;token=8a1748bd-f5a8-4572-93b8-82d68b9f1f7a" alt=""><figcaption><p>Overview Executive Dashboard</p></figcaption></figure>

***

#### **Overall Health**

Indicates, in a scaled format, the overall average of Info Security, Risk Exposure, Maturity, and Mitre indicators.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FnIEK3kvNIdEhKKC2Ymwg%2FScreenshot%202023-12-26%20at%2020.10.34.png?alt=media&amp;token=5d986962-b4ed-4fd9-9688-ea8ff3538976" alt="" width="375"><figcaption><p><strong>Info Security</strong></p></figcaption></figure>

***

#### **Info Security**

Average of coverage indicators for relations, event types, and private playbooks.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FrN1pYzZ1ospFqgJn8RI7%2FScreenshot%202023-12-26%20at%2020.10.46.png?alt=media&amp;token=40589608-5a73-4266-b90a-04e2c61d51dd" alt="" width="197"><figcaption><p>Info Security</p></figcaption></figure>

***

#### **Risk Exposure**

Checks the coverage of the time for first treatment, measuring its compliance with the standards set in the setup. The closer to 0%, the better the indicator.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FaeJyreD8AeZCXUIHALCl%2FScreenshot%202023-12-26%20at%2020.10.54.png?alt=media&amp;token=051ddabf-445c-4ce9-be95-12b47d752b94" alt="" width="197"><figcaption><p>Risk Exposure</p></figcaption></figure>

***

#### **Maturity**

Average of indicators in the Security Operation graph, rated on a scale of up to 5 points.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FPbbaOc2Vqm1YBNF58Tpn%2FScreenshot%202023-12-26%20at%2020.11.02.png?alt=media&amp;token=da87b7ef-088a-465f-a883-ae2d839f5a03" alt="" width="197"><figcaption><p>Maturity</p></figcaption></figure>

***

#### **Mitre**

Calculates the coverage of correlation rules for techniques and sub-techniques listed in Mitre.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2F4UkSHdslCFuVoAbvZgMO%2FScreenshot%202023-12-26%20at%2020.11.10.png?alt=media&amp;token=4235896f-d3dc-4708-9597-85a2b7e8df4e" alt="" width="197"><figcaption><p>Mitre</p></figcaption></figure>

***

#### **Attack Vector**

Visual representation of the treatment of events by data source, their attack vectors, and related results in the confusion matrix.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FhwqDJHW1mUEouvAQY9gk%2FScreenshot%202023-12-26%20at%2019.16.38.png?alt=media&amp;token=c5fdf5ed-06e7-413d-b750-fdc78b1d3aad" alt=""><figcaption><p>Attack Vector</p></figcaption></figure>

***

#### Events x Incidents

Visual representation of confirmed incidents, arising from events received by the monitoring system, demonstrating effectiveness in reducing manual labor.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2F5Z3DqSHCAMECmg5VeoEp%2FScreenshot%202023-12-26%20at%2019.17.08.png?alt=media&amp;token=4c8cb1f0-dddc-4bfc-b380-2f0d8c026660" alt="" width="563"><figcaption><p>Events x Incidents</p></figcaption></figure>

***

#### Quality KPIs:&#x20;

* Average Time To Detect An Incident (MTTD): The average time to identify an incident from the generation of the alert.&#x20;
* Average Time To Respond To An Incident (MTTR): A performance indicator of the security team measuring the time from the opening of the incident to the start of treatment.&#x20;
* Average Time To Contain An Incident (MTTC): The time it takes the team from identification to the start of the threat blocking phase.&#x20;
* Average Time To Repair (MTTR): The time required to fix the problems and eradicate the threat, returning the environment to a safe state.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FVvgvmzjmkzqjHGANzUMR%2FScreenshot%202023-12-26%20at%2019.17.26.png?alt=media&amp;token=8854fc97-9459-4df1-8406-4163c342e5e1" alt="" width="563"><figcaption><p>Quality KPIs</p></figcaption></figure>

***

#### Incidents By Status

Number of incidents distributed by each type of status.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2F9X0O3Lg8YuUtKScoFtg3%2FScreenshot%202023-12-26%20at%2019.17.56.png?alt=media&amp;token=35bf714a-ba6f-4179-a9de-3ceae95b7143" alt="" width="563"><figcaption><p>Incidents By Status</p></figcaption></figure>

***

#### Confusion Matrix

The number of alerts in each status of the confusion matrix.&#x20;

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FEqEZQcDFxZWrXPaBZe04%2FScreenshot%202023-12-26%20at%2019.18.10.png?alt=media&amp;token=622e3723-4972-4350-aa32-d38d4542b896" alt="" width="563"><figcaption><p>Confusion Matrix</p></figcaption></figure>

***

#### Security Operation

Visual representation, with a color rule, indicating the compliance level of various indicators, with descriptions available when hovering over their titles.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FRGpZvRXHDDp6T41h4Z6i%2FScreenshot%202023-12-26%20at%2019.59.38.png?alt=media&amp;token=876e84fd-bd43-46b7-aa37-36aabaf8e4a2" alt=""><figcaption><p>Security Operation</p></figcaption></figure>

* **Continuous Monitoring**
  * **Monitoring Systems**
    * **Relations:** Coverage of treatment of relations in the correlation rules.
  * **Data Sources**
    * **Correlation Rules:** Coverage if each event type is linked to at least one correlation rule.
  * **Mitre Framework**
    * **Tactics:** Coverage if each technique has at least one correlation rule.
    * **Techniques:** Coverage if there is at least one correlation rule linked to the technique.
* **Incident Response**
  * **Playbooks**
    * **Initial Playbooks:** Coverage if each correlation rule has at least one initial playbook.
    * **Advanced Playbooks:** Coverage if each active customer has at least one advanced type playbook.
  * **Continuous Operation**
    * **SLA:** Contracted SLA coverage percentage coverage.
    * **Quality of Service:** Maximum average rating coverage.
    * **Response Time:** Optimal response time coverage.
* **Customer Management**
  * **Continuous Operation**
    * **Requests:** Coverage of request processing, considering open/closed.
    * **SLA:** Contracted SLA coverage percentage coverage.
    * **Response Time:** Optimal response time coverage.
* **Automatic Response**
  * **Automatic Treatment Engine**
    * **First Response:** Mean Time To Treatment an Alert.
    * **Workload Reduction:** Workload Reduction in Percentage.

{% hint style="warning" %}
**Color Standards for Performance Indicators:**

* **Green (Excellent Performance):** Indicates a performance that is equal to or greater than 90%. This green color standard is used to represent high efficiency or compliance, signifying that the indicator is operating at an optimal level.
* **Orange (Moderate Performance):** Represents a performance between 60% and 89.99%. The orange color is used for indicators that are performing moderately, suggesting there is room for improvement, but the performance is still acceptable.
* **Red (Insufficient Performance):** Used for performances below 60%. The red color alerts to an unsatisfactory performance, indicating that the indicator is below an acceptable level and needs immediate attention for improvement.
* **Gray (Inactive):** Applied to indicators that are currently inactive. The gray color signals that the indicator is not in use or does not have sufficient data for performance evaluation at the moment.
  {% endhint %}

***
