February 20, 2006

Example IT Control Metrics to Be Considered by Audit Committees

The IT security control metrics are intended to enable boards, management, and technical staff to monitor the status and progress of their organization’s information security program over time. This guide provides two lists of metrics: The first for board members, and the second to help management implement the information security goals and policies established by the board.