Development of Performance Metrics
Once the decision is made to increase the electronic security, there is a tendency to start researching viable technologies immediately — but don’t do it! Like any good realtor would tell you, don’t go house shopping until you know what you want and what you can afford (and really need), otherwise you’re likely to end up with a flashy house that is too expensive and doesn’t meet your needs.
In much the same way there are a lot of technologies out there that look very enticing but could become very costly and restrict your ability to implement other technologies in the future. Before you start looking at solutions, it’s smart to develop a list of metrics to score potential solutions.
Performance metrics can generally be broken down into one of seven categories:
- Functionality – These identify how the system will function and typically carry the most weight in the decision-making process. These can include metrics such as device range, rate, speed, coverage and capacity.
- Environmental – These identify how the system holds up to the elements and typically includes metrics such as ingress protection (IP) ratings, temperature ratings and vandal resistance.
- Usability – This include metrics such as ease of installation, ability to integrate with other systems, etc.
- Communication – This includes metrics such as supported communication protocols, data encryption standards, bandwidth and storage used.
- Costing – This includes purchase price, installation cost, ongoing maintenance, training and total cost of ownership.
- Viability – This includes metrics such as manufacturer’s years in business, minimum number of units deployed in similar environments and minimum technology readiness level.
- Business Value Add - Are there any value adds beyond security to consider, such as increased operational effectiveness, decreased insurance premiums or increased customer satisfaction.
Performance metrics should be developed with feedback from as many stakeholders as possible. Stakeholders will vary from organization to organization, but typical roles include: systems and security operators, operations, information technology, compliance, law enforcement liaisons, engineering and executive leadership.
All these stakeholders to do not necessarily need to be involved in the day-to-day execution of the project; however, soliciting these stakeholders for feedback on system criteria they would like to see will help an organization obtain buy-in on the project. It may also be possible to earn some goodwill by providing a benefit beyond security to some of the stakeholders.
The more each metric can be understood and quantified relevant to the individual stakeholders, the better. This will better inform decisions on which technologies to implement and how to implement them to maximize system effectiveness across the entire organization.