Organizations use three types of measures:
• Those that determine the effectiveness of the execution of information security policy, most commonly issue-specific security policies
• Those that determine the effectiveness and/or efficiency of the delivery of information security services, whether they be managerial services such as security training, or technical services such as the installation of antivirus software
• Those that assess the impact of an incident or other security event on the organization or its mission.
Performance measures are increasingly required in today's regulated information security environment. It is no longer sufficient to simply assert effective information security an organization must demonstrate that it is taking effective measures in the spirit of due diligence. According to NIST Special Publication 800-55 revision 1., Performance Measures in Information Security, the following factors must be considered during development and implementation of an information security performance management program: