Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
pub:company:scorecard [21.07.2026 13:29] – Add ISO 20000-1 service and security metrics to Company Scorecard Predrag Tasevskipub:company:scorecard [21.07.2026 13:39] (current) – Enhance Scorecard with ISO standards context and improved navigation Predrag Tasevski
Line 21: Line 21:
 ===== Company Scorecard ===== ===== Company Scorecard =====
  
-^ # ^ Metric ^ Owner ^ Weekly Target ^ Tool / Source ^ Category ^ +^ # ^ Metric ^ Owner ^ Weekly Target ^ Tool / Source ^ Category ^ Standard 
-| 1 | New trial signups | Predrag | 3 | Mautic / Matomo | Business | +| 1 | New trial signups | Predrag | 3 | Mautic / Matomo | Business | — 
-| 2 | MRR (Monthly Recurring Revenue) | Predrag | Track weekly delta | [[https://erp.unicis.tech|Dolibarr]] | Business | +| 2 | MRR (Monthly Recurring Revenue) | Predrag | Track weekly delta | [[https://erp.unicis.tech|Dolibarr]] | Business | — 
-| 3 | Open support tickets (unresolved >48h) | Predrag | < 5 | FreeScout | Business | +| 3 | Open support tickets (unresolved >48h) | Predrag | < 5 | FreeScout | Business | — 
-| 4 | GitHub PRs merged (platform) | Peter | ≥ 3 | GitHub | Product | +| 4 | GitHub PRs merged (platform) | Peter | ≥ 3 | GitHub | Product | — 
-| 5 | EU project deliverables on track (%) | Alexander | 100% | [[https://scrum.unicis.tech|OpenProject]] | Projects | +| 5 | EU project deliverables on track (%) | Alexander | 100% | [[https://scrum.unicis.tech|OpenProject]] | Projects | — 
-| 6 | Platform uptime (%) | Peter | ≥ 99.5% | [[https://status.unicis.tech|status.unicis.tech]] / Grafana | Service | +| 6 | Platform uptime (%) | Peter | ≥ 99.5% | [[https://status.unicis.tech|status.unicis.tech]] / Grafana | **Service** | [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] 
-| 7 | Newsletter open rate (last send) | Ksenija | ≥ 35% | Mautic | Marketing | +| 7 | Newsletter open rate (last send) | Ksenija | ≥ 35% | Mautic | Marketing | — 
-| 8 | Active paying organisations | Predrag | Track weekly delta | [[https://erp.unicis.tech|Dolibarr]] | Business | +| 8 | Active paying organisations | Predrag | Track weekly delta | [[https://erp.unicis.tech|Dolibarr]] | Business | — 
-| 9 | Critical security alerts (CrowdSec) | Peter | 0 unresolved | Grafana / Matrix alerts | Security | +| 9 | Critical security alerts (CrowdSec) | Peter | 0 unresolved | Grafana / Matrix alerts | **Security** | [[pub:trust_center:iso_27001_overview|ISO 27001]] 
-| 10 | Website organic sessions (week-over-week) | Ksenija | ↑ vs prior week | Matomo | Marketing | +| 10 | Website organic sessions (week-over-week) | Ksenija | ↑ vs prior week | Matomo | Marketing | — 
-| **11** | **P1 incident response time (avg)** | **Peter** | **≤ 2 hours** | **FreeScout / incident log** | **Service** | +| **11** | **P1 incident response time (avg)** | **Peter** | **≤ 2 hours** | **FreeScout / incident log** | **Service** | **[[pub:trust_center:iso_20000_1_overview|ISO 20000-1]]** | 
-| **12** | **Security patch deployment (critical)** | **Peter** | **≤ 7 days** | **Vulnerability scanner log** | **Security** | +| **12** | **Security patch deployment (critical)** | **Peter** | **≤ 7 days** | **Vulnerability scanner log** | **Security** | **[[pub:trust_center:iso_27001_overview|ISO 27001]]** | 
-| **13** | **Access provisioning time (new hires)** | **Alexander** | **≤ 1 day** | **Access control log** | **Security** | +| **13** | **Access provisioning time (new hires)** | **Alexander** | **≤ 1 day** | **Access control log** | **Security** | **[[pub:trust_center:iso_27001_overview|ISO 27001]]** | 
-| **14** | **Deployment success rate (%)** | **Peter** | **≥ 99%** | **GitHub Actions / incident log** | **Service** |+| **14** | **Deployment success rate (%)** | **Peter** | **≥ 99%** | **GitHub Actions / incident log** | **Service** | **[[pub:trust_center:iso_20000_1_overview|ISO 20000-1]]** | 
 + 
 +====== Understanding the Categories ====== 
 + 
 +**Business & Product:** Core company health (revenue, signups, code quality) 
 + 
 +**Service** (ISO 20000-1): Platform reliability and availability commitments 
 +  * See [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018 Overview]] for details on service commitments 
 +  * See [[pub:company:service_strategy|Service Strategy]] for SLA targets 
 + 
 +**Security** (ISO 27001): Information security and incident response performance 
 +  * See [[pub:trust_center:iso_27001_overview|ISO 27001:2022 Overview]] for details on security commitments 
 +  * See [[pub:trust_center:isms_policy|Information Security Policy]] for commitment details
  
 ---- ----
Line 49: Line 61:
   * Outbound partner conversations (calls/emails sent)   * Outbound partner conversations (calls/emails sent)
   * Support tickets unresolved >48h (FreeScout)   * Support tickets unresolved >48h (FreeScout)
 +
 +**Leadership Role:** [[pub:company:accountability_chart|SMS Sponsor & ISMS Sponsor]] — Oversees both [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] and [[pub:trust_center:iso_27001_overview|ISO 27001]] systems
  
 === Peter — Technical Development & Service Delivery === === Peter — Technical Development & Service Delivery ===
Line 55: Line 69:
   * Open critical bugs (P0/P1) unresolved   * Open critical bugs (P0/P1) unresolved
   * Platform uptime %   * Platform uptime %
-  * **P1 incident response time (average)** ← NEW (ISO 20000-1) +  * **P1 incident response time (average)** ← [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] 
-  * **Security patch deployment time (critical vulns)** ← NEW (ISO 27001) +  * **Security patch deployment time (critical vulns)** ← [[pub:trust_center:iso_27001_overview|ISO 27001]] 
-  * **Deployment success rate %** ← NEW (ISO 20000-1)+  * **Deployment success rate %** ← [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] 
 + 
 +**Leadership Role:** [[pub:company:accountability_chart|Service Delivery Owner & Information Security Implementation]] — Responsible for service reliability and security controls
  
 === Alexander — Stakeholder & Support / Service Delivery === === Alexander — Stakeholder & Support / Service Delivery ===
Line 64: Line 80:
   * Stakeholder communications sent this week   * Stakeholder communications sent this week
   * Community GitHub activity (issues opened/closed/commented)   * Community GitHub activity (issues opened/closed/commented)
-  * **P2 incident response time (average)** ← NEW (ISO 20000-1) +  * **P2 incident response time (average)** ← [[pub:trust_center:iso_20000_1_overview|ISO 20000-1]] 
-  * **Access provisioning time (new hires, days)** ← NEW (ISO 27001)+  * **Access provisioning time (new hires, days)** ← [[pub:trust_center:iso_27001_overview|ISO 27001]] 
 + 
 +**Leadership Role:** [[pub:company:accountability_chart|Support Manager & Access Control Manager]] — Responsible for operational service delivery and security access control
  
 === Ksenija — Marketing & SEO Strategy === === Ksenija — Marketing & SEO Strategy ===
Line 72: Line 90:
   * Newsletter open rate (Mautic, last send)   * Newsletter open rate (Mautic, last send)
   * New content published (blog posts / social posts)   * New content published (blog posts / social posts)
 +
 +**Leadership Role:** [[pub:company:accountability_chart|Communications & Security Awareness Lead]]
  
 ---- ----
Line 97: Line 117:
 ---- ----
  
-[[pub:company:vision_traction_organizer|→ Back to V/TO]] | [[pub:company:traction|→ Rocks & Level 10 Meetings]] | [[internal:company:accountability_chart|→ Accountability Chart]] | [[pub:trust_center:iso_20000_1_overview|→ ISO 20000-1 Service Metrics]] | [[pub:trust_center:iso_27001_overview|→ ISO 27001 Security Metrics]]+===== Related Standards & Documentation ===== 
 + 
 +  * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]] — IT Service Management System (service metrics) 
 +  * [[pub:trust_center:iso_27001_overview|ISO 27001:2022]] — Information Security Management System (security metrics) 
 +  * [[pub:company:service_strategy|Service Strategy & Commitments]] — SLA targets and how we deliver 
 +  * [[pub:trust_center:isms_policy|Information Security Policy]] — Security commitments and governance 
 +  * [[pub:trust_center:risk_framework|Risk Assessment Framework]] — How we manage risks affecting these metrics 
 +  * [[pub:company:accountability_chart|Accountability Chart]] — Leadership roles and responsibilities 
 +  * [[pub:company:traction|Quarterly Planning & Reviews]] — How we use metrics to improve 
 + 
 +---- 
 + 
 +[[pub:company:vision_traction_organizer|→ Back to V/TO]] | [[pub:company:traction|→ Rocks & Level 10 Meetings]] | [[pub:company:accountability_chart|→ Accountability Chart]] | [[pub:trust_center:iso_20000_1_overview|→ ISO 20000-1 Service Metrics]] | [[pub:trust_center:iso_27001_overview|→ ISO 27001 Security Metrics]]
  
 ---- ----