Home/Blog/12 Access Review Metrics Every CISO Should Track Quarterly
Metrics

12 Access Review Metrics Every CISO Should Track Quarterly

Every CISO gets asked the same question by the audit committee: is the access review program working? The honest answer requires numbers, not adjectives. These are the twelve that actually predict outcomes: audit findings, breach exposure, and license waste.

Track all twelve quarterly. Publish the four completion metrics inside the org. The rest live on your desk.

Which metrics track program completion?

Four metrics. These are the ones you publish and pin to a dashboard.

  • Campaign duration. Days from launch to evidence bundle export. Target: 10 business days for quarterly reviews.
  • Reviewer completion rate at cutoff. Percentage of assigned reviewers who submitted a decision on every assigned entitlement by the decision deadline. Target: 95%+.
  • Escalation rate. Percentage of reviewers who required a manager-of-reviewer escalation. Target: 10 to 20%. Below 10%, you are being too slack on the deadline. Above 25%, reviewer routing is wrong.
  • Revocation execution rate at close. Percentage of "revoke" decisions confirmed executed in the source system by campaign close. Target: 95%+.

These four are the operational heartbeat. If any one drops for two cycles running, the program is drifting.

Which metrics measure standing access risk?

Four metrics. These live on the CISO's desk and drive one-off remediation projects.

  • Dormant privileged access rate. Privileged entitlements not used in 90 days, divided by total privileged entitlements. Target: under 3%.
  • Orphaned account rate. Active accounts with no assigned owner or manager, divided by total active accounts. Target: zero. Every orphaned account is a finding waiting to happen.
  • Segregation of duties (SoD) conflict count. Users holding entitlements that together violate an SoD rule (approve and pay, develop and deploy to prod, etc.). Target: zero unremediated. Any non-zero requires a compensating control and documentation.
  • Standing privileged access rate. Privileged entitlements granted permanently rather than time-bound through just-in-time elevation. Target: falling every cycle. Best-in-class programs have under 20% of privileged access standing.

These four are the risk metrics an auditor or a red team lead cares about most.

Which metrics predict audit posture?

Four metrics. These roll up to the audit committee.

Metric Definition Target
Access-related findings per SOC 2 cycle Findings in Type II reports tied to CC6.1 to CC6.3 Zero, two cycles in a row
Evidence completeness Percentage of campaigns where all six evidence artifacts export at close 100%
Mean time to revoke (MTTR) Days from reviewer clicking revoke to access confirmed removed in source system Under 5 business days
Control coverage Percentage of in-scope systems included in the campaign 100% of in-scope, gaps documented for out-of-scope

MTTR is the load-bearing metric of the four. Every other audit posture metric can look good with a broken MTTR, but a broken MTTR guarantees an audit finding.

What target ranges signal a healthy program?

Consolidated view. Snapshot this each quarter.

  • Campaign duration: 10 business days.
  • Reviewer completion at cutoff: above 95%.
  • Escalation rate: 10 to 20%.
  • Revocation execution rate: above 95%.
  • Dormant privileged access: under 3%.
  • Orphaned account rate: zero.
  • SoD conflicts unremediated: zero.
  • Standing privileged access: trending down, under 20% for best-in-class.
  • Access-related audit findings: zero.
  • Evidence completeness: 100%.
  • Mean time to revoke: under 5 business days.
  • Control coverage: 100% of in-scope systems.

You will not hit all twelve targets in year one. You should be moving toward every one of them by year two.

Which metrics drive the fastest behavior change?

Two metrics move behavior faster than any others.

  • Reviewer completion rate, published by manager. When a manager sees their team's completion rate next to the other teams' rates, completion changes within one cycle. Do not overthink the incentive structure; visibility is the incentive.
  • Dormant privileged access, published by system owner. When the AWS account owner sees "you have 27 dormant admin entitlements", they start requesting revocations rather than resisting them. The metric shifts them from defense to cleanup.

Every other metric matters, but these two are the ones that shift the culture. Publish them monthly, not quarterly.

How do you handle metric gaming?

Every metric can be gamed. Two show up first.

  • Reviewer completion rate gets gamed by bulk approve. Countermeasure: pair completion with revocation rate cycle-over-cycle. A reviewer with 100% completion and 0% revocations two cycles running is rubber-stamping. Flag the pattern, not the reviewer.
  • MTTR gets gamed by marking tickets closed before the access is actually gone. Countermeasure: validate revocation state in the source system, not in the ticket queue. If the ticket says closed and the access is still live, the ticket is not closed for MTTR purposes.

A metric that cannot be validated against the actual state of the system will be gamed. Build validation into every metric that matters.

What is the reporting cadence for these metrics?

Three cadences.

  • Weekly. Campaign duration and reviewer completion rate during an active campaign. Consumed by the campaign owner and the CISO.
  • Monthly. Reviewer completion rate by manager, dormant privileged access by system owner, MTTR by system. Consumed by managers and system owners.
  • Quarterly. All twelve metrics, trended. Consumed by the audit committee and the security leadership.

Cadence matters as much as the metrics. A metric read once a year is not an operating metric.

The mistake to avoid

Most CISOs pick five metrics that are easy to measure and ignore the seven that matter. Campaign duration and reviewer completion rate are easy to measure. Dormant privileged access, orphaned accounts, and mean time to revoke require pulling data from the source systems and validating state, which is harder. But it is the harder metrics that predict breach exposure and audit findings. If your dashboard only tells you whether the campaign closed, you have a paperwork metric, not a security metric. Add the risk metrics before the audit committee asks why you did not.

ciso metricsaccess reviewidentity governancekpigrc dashboard

Frequently asked questions

Which of these twelve is the most important?

Mean time to revoke (MTTR). It is the single metric that most directly reflects whether the review is real. If MTTR is under 5 business days, the revocation pipeline is working. If it is over 30 days, the review is producing decisions that never execute, which is the definition of audit theater. Everything else is context around MTTR.

How do you measure dormant privileged access?

For each privileged entitlement (admin, owner, superuser, IAM policies granting write on regulated data), pull the last-used timestamp from the source system's audit log. Divide entitlements not used in 90 days by total privileged entitlements. Target under 3%. Above 10%, dormant privilege is your dominant risk, and any breach post-mortem will call it out.

Do we need a dashboard tool for these metrics?

Not initially. A monthly CSV export dropped into a spreadsheet or Looker board is enough to run the program for the first year. Dashboards matter when you have to show the board or an auditor a trendline; before then, the metric matters more than the visualization. Start with the export, not the tool.

How do these metrics map to SOC 2 or ISO 27001?

Directly. Campaign duration and reviewer completion rate map to CC6.1 (access controls). Revocation execution and MTTR map to CC6.3 (removal on role change). SoD conflicts map to CC6.1 and CC6.2. Evidence completeness and control coverage map to the framework's evidence requirements. Auditors are increasingly asking for these metrics as part of the walkthrough.

Should we publish these metrics internally?

Yes, at least the four completion metrics. Reviewer completion rate published back to the reviewer's manager changes behavior within one cycle. Dormant privileged access published to system owners changes behavior within two cycles. The metrics that do not get published stay private and stay bad.

Close access reviews in days, not quarters

Orvaron pulls entitlements from every system, routes reviews to the right manager, and executes revocations in the source app so evidence builds itself.

Request early access