A protection level agreement is an agreed, funded target for a security outcome, negotiated between security leadership and the business. It borrows its shape from the service level agreement, but the thing being committed to is a level of protection rather than uptime or response time.
Start with an outcome-driven metric. Establish where the organization sits today. Then show the business what a higher level would cost and what a lower level would save.
The business picks. That choice, written down, is the protection level agreement.
The mechanism matters more than the number. A PLA turns “are we secure enough” into a decision with a named owner and a price attached. It also ends the argument where security is blamed for an outcome the organization declined to fund.
An agreed target, in the metric’s own units, with a date.
A named business owner who signed for it, not just a security owner who reports on it.
A stated cost of moving between levels.
A measurement method that will not quietly change. If the underlying formula shifts, the agreement becomes unfalsifiable, and both sides know it.
Most PLA programs die at the fourth requirement. Someone commits to a target in a steering committee, and eighteen months later nobody can reconstruct how the baseline was calculated. The vendor changed, the analyst left, the spreadsheet has four versions.
At that point the agreement is not enforceable and quietly stops being mentioned.
Metric Maestro keeps the definition of the agreed metric fixed and computes it the same way each period, whatever happens underneath. When a source tool is replaced, the mapping changes and the metric does not.
Every value can be opened and traced to the records that produced it, so a business owner who disputes a figure gets an answer instead of an assurance. That is the difference between a protection level the organization actually holds itself to and a slide from a workshop two years ago.
From the blog