Step 1
Define reporting window and metric baseline
Use a fixed window (for example 30/60/90 days) so trend comparisons are stable and defensible.
- Select reporting period that matches governance and board cadence.
- Confirm MTTR includes only resolved critical/high findings in-window.
- Confirm open backlog metrics use active lifecycle states only.