Organizations use three types of measures:
Those that determine the effectiveness of the execution of information security policy, most commonly issue-specific security policies
• Those that determine the effectiveness and/or efficiency of the delivery of information security services, whether they be managerial services such as security training, or technical services such as the installation of antivirus software
• Those that assess the impact of an incident or other security event on the organization or its mission