PM-06 ยท Measures of Performance

Control Description

Develop, monitor, and report on the results of information security and privacy measures of performance.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53
organization
Assurance
Control Statement
The control requirements

Develop, monitor, and report on the results of information security and privacy measures of performance.

Supplemental Guidance

Measures of performance are outcome-based metrics used by an organization to measure the effectiveness or efficiency of the information security and privacy programs and the controls employed in support of the program. To facilitate security and privacy risk management, organizations consider aligning measures of performance with the organizational risk tolerance as defined in the risk management strategy.

Related NIST Controls
Other NIST 800-53 controls related to this one