---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# CISO dashboard

# CISO dashboard {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

This dashboard reveals the overall security posture of your organization, including
security vulnerability and incidents.
Figure 1. Security Operations Center tab Figure 2. Vulnerability Profile tab Figure 3. Security Controls Profile tab Figure 4. Business Risk Profile tab

## End users and roles {#ciso-dashboard__section_pth_zj2_n2b}

{#ciso-dashboard__table_nvn_dk2_n2b__entry__2}

| End user and goal | Required role |
|-|-|
| CISO: Needs clear visibility regarding the current security posture of the overall organization | sn_si.ciso |
[ ]

{#ciso-dashboard__table_nvn_dk2_n2b}

## CISO dashboard indicators {#ciso-dashboard__section_wnx_mm2_n2b}

The CISO dashboard presents the following key performance indicators:

SI - Average Time to Identify
:   A 7-day average of the time in minutes it takes to identify a security incident,
    calculated
    daily.

Average Time to Contain
:   A 7-day average of the time in minutes it takes to contain a security incident, calculated
    daily.

Average Time to Eradicate
:   A 7-day average of the time in minutes it takes to eradicate a security incident,
    calculated daily. Both Average Time to Contain and Average Time to Eradicate are based on the
    indicator SI - Average Duration Time broken down by Security Incident State.

New Security Incidents This Week
:   The weekly sum of the score of the daily Number of new security incidents
    indicator.

Security Incidents Closed (weekly)
:   The 7-day running sum of the daily Number of closed security incidents indicator.

New Security Incidents by Priority
:   Daily breakdown of the Number of new security incidents indicator by Priority.

New vs Closed Security Incidents (weekly) volume
:   The 7-day running sum time series of the Number of new incidents indicator charted against
    the 7-day running sum time series of the Number of closed incidents
    indicator.

Security Incident Heatmap
:   A global map showing the number of open security incidents in each
    country.

Security Incident Treemap
:   An interactive treemap where you can select to see:

    * Security incidents per business service, broken down by business criticality
    * Security incidents broken down by category or subcategory of incident
    * Security incidents per assignment group or per assignee
    * 'Victim stats' of security incident per affected resource or affected user
    {#ciso-dashboard__ul_tft_mv2_n2b}

## Breakdowns {#ciso-dashboard__section_njs_bnm_n2b}

The following breakdowns apply to the indicators on the dashboard:

* Business criticality
* Security Group
* Security Incident Age
* Security Incident Category
* Security Incident Close Code
* Security Incident Priority
* Security Incident State
* SI - Business Service
* Vulnerability
{#ciso-dashboard__ul_vyr_2nm_n2b}

## Data visualizations {#ciso-dashboard__section_qgs_3nm_n2b}

The dashboard includes the following visualizations:
{#ciso-dashboard__table_f1l_tnm_n2b__entry__3}

| Title | Type | Description |
|-|-|-|
| Security Incidents Open for More Than 30 Days by Assignment Group and State | Heatmap ![Heatmap icon]() | Displays models with the most vulnerable items. |
| Risks by Category | Donut ![Donut icon]() | Lists the age of reopened vulnerable items. |
| Citations by Authority Document | Donut ![Donut icon]() | Number of active vulnerabilities |
| Security Incidents With Assignee That is not Active | Heatmap ![Heatmap icon]() | Displays the number of open vulnerable items associated with vulnerabilities, (Common Vulnerability Enumeration (CVE) records), from most to least. |
| Security Incidents Not Updated for More Than 30 Days by Assignment Group and State | Heatmap ![Heatmap icon]() | Displays publishers with the most vulnerable items. |
| Vulnerability Map | Map ![Map icon]() | A world map showing vulnerabilities by location |
| Most Vulnerable Models | Donut ![Donut icon]() | The applications that contain the most vulnerabilities |
| Most Vulnerable CIs by Class | Donut ![Donut icon]() | CIs by server type |
| Services with Critically Significant Vulnerabilities | List ![List icon3]() |   |
| Non-compliant profiles | Bar ![Bar icon]() | Non-compliant controls by profile |
| Control Overview | Bar ![Bar icon]() | Number of compliant and non-compliant controls |
| Policy Exceptions | List ![List icon3]() | Policy exceptions with priority, owner, and short description |
| Risks by Category | Donut ![Donut icon]() | The number of risks in each category of risk |
| Inherent Risk | Bubble ![Bubble icon]() | Inherent SLE vs Inherent ARO |
| Residual Risk | Bubble ![Bubble icon]() | Residual SLE vs Residual ARO |
| Moderate, High, and Very High Risks | Scores![Latest score icon]() | The numbers of moderate, high, and very high risks, respectively |
| Risk by Profile | Stacked Bar![Stacked bar icon]() | Risk count where you can select what to group by and what to stack by |
[ ]

{#ciso-dashboard__table_f1l_tnm_n2b}
**Related concepts**   

* [Security Incident Management Premium dashboard](https://servicenow-prod.fluidtopics.net/X9KMBpuZaioLg~UX7grKEw "This dashboard uses advanced Platform Analytics visualizations to aid security managers to track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery. The licensed version of Performance Analytics is therefore required.")
* [Security Incident Management dashboard](https://servicenow-prod.fluidtopics.net/ZGugWm4AC0IojziXGTf_Kw "With this dashboard, security managers can easily track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.")
* [Security Incident Explorer dashboard](https://servicenow-prod.fluidtopics.net/wxeQe7okNlX6NLpBsBC6eg "With this dashboard, security managers are able to view security incidents summarized and grouped by category, subcategory, location, priority and business impact. These views let managers quickly gain insight into the frequency in which attacks are occurring and which business services are affected.")
* [Security Operations Efficiency dashboard](https://servicenow-prod.fluidtopics.net/PFzg1byjG2xBY6TH5LSdmQ "Security operations center (SOC) managers can view overall efficiency metrics and measure the individual performance of the SOC team members in the organization.")

