1. ISACA
CISM Review Manual
15th Edition. Chapter 3
Section: "Information Security Program Management." The manual states that metrics are essential for "measuring
monitoring
and reporting on the effectiveness of information security controls and the overall information security program." It emphasizes that metrics provide assurance to stakeholders that security objectives are being achieved.
2. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-55 Rev. 1
Performance Measurement Guide for Information Security. Section 2.1
"Purpose of an Information Security Performance Measurement Program
" explicitly states: "An information security performance measurement program helps an organization determine the effectiveness of its information security program
policies
and controls..."
3. ISACA
COBIT 2019 Framework: Introduction and Methodology. The framework's core principles revolve around governance and management objectives. The "Monitor
Evaluate and Assess" (MEA) domain
particularly MEA01
focuses on monitoring performance and conformance to ensure that enterprise and governance objectives are met
which is a direct measure of effectiveness.