PM-6: Measures of Performance

PM-06 requires your organization to develop, monitor, and report outcome-based metrics that measure how well your information security and

Quick-reference card

FieldValue
Control IDPM-06
Control NameMeasures of Performance
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PM-06 requires your organization to develop, monitor, and report outcome-based metrics that measure how well your information security and privacy programs actually perform. Most organizations track activity counts (scans completed, patches applied, tickets closed) but never connect those numbers to whether the security program is reducing risk. This control exists to close that gap.

In practice, this means defining metrics tied to your risk tolerance, collecting measurement data on a recurring schedule, and presenting results to leadership in a format that drives decisions. You aren’t just counting controls that exist. You’re measuring whether those controls are producing the outcomes they were designed to deliver.

The requirement applies to both information security and privacy programs. Each needs its own set of measures of performance that reflect its specific objectives, as outlined in the broader NIST SP 800-53 framework. Information security measures might track vulnerability remediation timelines or incident containment speed, while privacy measures might focus on data subject request fulfillment rates or consent management accuracy.

Critically, the results need to feed back into your risk management strategy so leadership can adjust priorities based on evidence rather than assumptions. This feedback loop is what separates PM-06 from a reporting exercise. The metrics you define should be specific enough that a declining trend triggers a documented investigation and response, not just a line on a quarterly slide deck.

Why it matters

Failure to maintain this control introduces audit risk during federal assessments, privacy compliance reviews, and any evaluation that checks whether your organization can demonstrate program effectiveness. This is especially visible in Program Management family reviews, where PM-06 evidence is a recurring audit checkpoint. Without defined measures of performance, you have no defensible way to show that your security and privacy investments are working.

The absence of outcome-based metrics also creates a governance blind spot. Leadership decisions about staffing, tooling, and program scope depend on reliable data. When that data doesn’t exist, resource allocation defaults to gut instinct or whoever makes the loudest case, neither of which produces consistent risk reduction over time.

Regulatory frameworks increasingly expect organizations to demonstrate measurable program outcomes, not just the presence of controls. An organization that can point to trending security metrics tied to its risk appetite has a fundamentally stronger compliance posture than one that lists controls without performance data.

Where this gap becomes most visible is during continuous monitoring assessments under FISMA or privacy impact evaluations under frameworks that require demonstrated program maturity. Assessors don’t just ask whether metrics exist. They ask whether the metrics have been used to change something, whether a declining trend triggered a resource shift, a control adjustment, or a documented risk acceptance decision.

What auditors flag

  • No documented measures of performance for either the information security program or the privacy program
  • Metrics that track activity volume (number of scans, number of training completions) without connecting to outcomes like risk reduction or incident response time
  • No evidence that measurement results have been reported to leadership or used to inform program decisions
  • Measures of performance not aligned with the organization’s risk management strategy or stated risk tolerance
  • Inconsistent or undocumented monitoring cadence, making trend analysis impossible
  • Privacy measures of performance missing entirely, even when information security metrics are present

How to implement

For your organization

The core challenge with PM-06 isn’t technical. It’s organizational. Most security teams can generate reports, but few have defined what “good” looks like for their program in measurable terms before those reports get built.

Step 1: Align metrics with your risk management strategy. Start by reviewing your risk management strategy and risk tolerance statements. Your measures of performance should directly reflect the outcomes your organization has committed to achieving. If your risk tolerance accepts a four-hour recovery time objective for critical systems, one of your cybersecurity metrics should track actual recovery times against that threshold.

Step 2: Define outcome-based metrics for both programs. Develop separate sets of measures for information security and privacy. Information security metrics might include mean time to remediate critical vulnerabilities, percentage of systems with current baseline configurations, or the ratio of detected incidents to those requiring escalation. Privacy metrics might track data subject request completion rates against regulatory deadlines, or the percentage of systems with current data processing impact assessments.

Step 3: Establish monitoring procedures. Document how each metric is collected, who owns the data source, and how often measurements occur. Automated collection through GRC platforms, SIEM dashboards, or vulnerability management tools reduces manual burden and improves consistency. The procedures should specify what constitutes a measurement period and how baselines are established for trend comparison. Without documented procedures, measurement becomes inconsistent across reporting periods, and auditors can’t verify that the data reflects actual program performance.

Step 4: Build a reporting cadence. Define who receives performance reports, how often, and in what format. Quarterly reporting to senior leadership is a common cadence, but the right interval depends on your organization’s size and program maturity. Reports should show trend data, not just snapshots, so decision-makers can distinguish between noise and meaningful shifts.

Step 5: Close the feedback loop. The results need to influence decisions. Document how performance data feeds back into your risk management strategy and program planning. If a metric shows cybersecurity performance declining in a specific area, there should be a defined process for investigating the root cause and adjusting controls or resources.

Common mistakes to avoid:

  • Treating this as a one-time exercise rather than a recurring operational process
  • Choosing metrics based on what’s available in current tools rather than what aligns with program objectives
  • Reporting raw numbers without interpretation or risk context
  • Failing to document the connection between measures of performance and the risk management strategy

Evidence examples

Evidence TypeExample Artifact
Program planInformation security program plan defining program objectives and associated performance targets
Program planPrivacy program plan documenting privacy-specific goals, metrics, and reporting requirements
Performance metrics documentationCatalog of information security measures of performance with definitions, data sources, collection frequency, and outcome thresholds
Performance metrics documentationCatalog of privacy measures of performance with definitions, data sources, collection frequency, and outcome thresholds
Measurement proceduresProcedures for developing, monitoring, and reporting measures of performance, including roles, tools, and escalation criteria
Risk management strategyRisk management strategy documenting organizational risk tolerance and the alignment of performance metrics to risk appetite
Performance reportsQuarterly or periodic reports showing trending measurement results with leadership sign-off and action items

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.3 Segregation of dutiesPartial
ISO 27001:20226.2 Terms and conditions of employmentPartial
  • CA-07 — Continuous Monitoring: provides the ongoing data feeds and automated measurements that supply input to your measures of performance.
  • PM-09 — Risk Management Strategy: defines the risk tolerance thresholds that your performance metrics should measure against.

Frequently asked questions

What is NIST SP 800-53 PM-06

PM-06 requires organizations to develop, monitor, and report outcome-based metrics that measure the effectiveness of their information security and privacy programs. These measures of performance must align with the organization’s risk tolerance as defined in its risk management strategy. The control applies to both information security and privacy programs independently, ensuring each has quantifiable indicators of program health.

What happens if PM-06 is not implemented

Without defined measures of performance, your organization cannot demonstrate to auditors or regulators that its security and privacy programs are achieving their intended outcomes. Assessors will flag the absence of documented information security and privacy metrics, trending reports, and evidence that measurement results inform leadership decisions. The result is a compliance gap that weakens your overall audit posture and limits your ability to justify program resources.

How do you audit PM-06

Auditors verify PM-06 by requesting documented information security measures of performance and privacy measures of performance, then confirming that monitoring procedures exist and that results have been reported to leadership. The assessment follows the NIST SP 800-53 assessment methodology. They examine whether the metrics are outcome-based rather than activity-based, whether monitoring occurs on a defined schedule, and whether the results align with the risk management strategy. Evidence of trend data and documented decisions informed by performance results strengthens the assessment outcome.

What are examples of information security measures of performance

Common examples include mean time to remediate critical vulnerabilities, percentage of systems meeting baseline configuration standards, incident detection-to-containment time, and phishing simulation failure rates tracked over time. Each metric should connect to a specific program objective documented in the information security program plan. The key distinction is that these measures track outcomes and effectiveness, not just activity counts like the number of scans or training sessions completed.

Experience superior visibility and a simpler approach to cyber risk management