This document provides guidance on developing and implementing performance measures to assess the effectiveness of information security controls and programs. It describes a process for establishing measures that are quantifiable and can be used to track performance over time. The measures developed should indicate how well security policies are implemented, how efficiently security controls operate, and the impact of any security issues. This will help organizations comply with laws like FISMA and use security metrics to improve practices and allocate resources. The guidance can be applied at the individual system or enterprise program level.