Organization should determine what to monitor and measure in terms of information security processes and controls. It's important to establish effective methods for monitoring, measurement, analysis, and evaluation to ensure valid and comparable results. The organization needs to specify when these monitoring and measuring activities should occur and assign responsibilities for these tasks. Documented information is required to serve as evidence of the results.
The organisation regularly evaluates the level of cyber security and the effectiveness of the information security management system.
Organisation has defined:
Effective metrics should be usable for identifying weaknesses, targeting resources better and assessing organisation's success / failure related to cyber security.