The studies of the socio-organizational aspects of information security are recent, particularly those that use quantitative methods. The lack of measurement items and constructs that are significant for information security is an issue that becomes apparent in the information security decision-making process. The development and reuse of quantitative metrics that support research on information security can increase the problem evaluation and decision making accuracy level.