CISSP GLOSSARY · SECURITY OPERATIONS

Key Risk Indicator (KRI)

A forward-looking metric that warns risk exposure is approaching an unacceptable level, triggering management action before loss occurs, unlike a KPI, which measures achieved performance.

A Key Risk Indicator (KRI) is a forward-looking metric that warns management that risk exposure is rising before a loss actually occurs. Examples include the number of unpatched critical systems, growth in privileged accounts, staff turnover in the security team, or the backlog of overdue audit findings. Each KRI is paired with a threshold; when the measurement crosses it, the organisation is drifting outside its risk appetite and management attention is triggered before the exposure turns into an incident.

The distinction the exam loves is KRI versus KPI. A key performance indicator looks backwards at achievement: how well something performed. A KRI looks forwards at exposure: how likely something is to go wrong. Patching completed this month is a KPI; systems still unpatched past their remediation deadline is a KRI. Good KRIs are measurable, comparable over time, and tied to specific risks, so a rising value maps to rising residual risk that decision makers can act on.

Exam relevance: if a scenario mentions an early warning that risk is increasing, thresholds that trigger escalation, or metrics reported to a risk committee, the answer is key risk indicator. If the metric measures how well a control or team performed, the answer is KPI. The confusable pair is directional: KPIs reward the past, KRIs warn about the future, and a question asking which metric tells the board that exposure is approaching tolerance limits wants the KRI.