Phase 1 of the measures development process identifies relevant stakeholders and their interests in information security measurement. The primary stakeholders are those with key information security responsibilities or data ownership. Secondary stakeholders, such as training and human resources personnel, may not be primarily responsible for information security, but have relevant tasks in some aspect of their' jobs.
Phase 2 of the measures -development process is to identify and document the information security performance goals and objectives that would guide security control implementation for the information security program of a specific information system