{"data":{"id":"PM-06","name":"Measures of Performance","family":"PM","family_name":"Program Management","withdrawn":false,"description":"Develop, monitor, and report on the results of information security and privacy measures of performance.","supplemental_guidance":"Measures of performance are outcome-based metrics used by an organization to measure the effectiveness or efficiency of the information security and privacy programs and the controls employed in support of the program. To facilitate security and privacy risk management, organizations consider aligning measures of performance with the organizational risk tolerance as defined in the risk management strategy.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"PM-06","name":"Measures of Performance","description":"Develop, monitor, and report on the results of information security and privacy measures of performance.","discussion":"Measures of performance are outcome-based metrics used by an organization to measure the effectiveness or efficiency of the information security and privacy programs and the controls employed in support of the program. To facilitate security and privacy risk management, organizations consider aligning measures of performance with the organizational risk tolerance as defined in the risk management strategy.","related_controls":["CA-07","PM-09"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Information Security Measures of Performance' to 'Measures of Performance'. Privacy added."}},"compliance_mappings":{"iso_27001_2022":["4.4","5.3","6.1","6.2","9.1","9.3","10.1","A.5.35","A.5.36"],"iso_27002_2022":["5.35","5.36"],"cobit_2019":["APO13","EDM02","MEA01","MEA02"],"pci_dss_v4":["12.4"],"nist_csf_2":["GV.OV-01","GV.OV-03","ID.IM-01","ID.IM-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(f)","Art. 32"],"apra_cps_234":["Para 27-28"],"mas_trm":[],"pra_op_resilience":["SS1/21-6.2","SS1/21-7.1"],"bsi_grundschutz":["ISMS.1"],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["5.35","5.36"],"rbi_csf":["Annex1.21","ITGRCA.21"],"fisc":["FISC.O7"],"lgpd_bcb":["BCB.Art.18","BCB.Art.19"],"hkma_tme1":["TME1.3.3","TME1.12.3"],"mlps_2":[],"dnb_good_practice":["DNB.5.2","DNB.14.1","DNB.16.2","DNB.16.4"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-16"],"cbuae":["CR-14"],"nca_ecc":["1-2","1-7","1-8"],"qatar_nia":["GV"],"sama_csf":["1.3","1.9","2.2"],"uae_ia":["T1"],"bog_cisd":["CISD-COMP","CISD-IV"],"bom_ctrm":["1.5","5.4"],"cbe_csf":["GOV-3"],"cbn_csf":["Part2.2","Part6.1","Part6.2","Part7.2"],"sa_js2":["JS2-5","JS2-9"],"bcbs_239":["Principle 12"],"eba_ict":["3.3.5"],"ffiec_is":["Appendix A","II.C.1","II.C.4","II.D","IV.A","IV.A.1","IV.A.4"],"hipaa_sr":["§164.308(a)(8)"],"nydfs_500":["500.2"],"sebi_cscrf":["AUDIT","CCI","GV.OV"],"cmmc_2":["CA"],"nerc_cip":[],"nrc_73_54":["73.54(d)"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["PROGRAM"],"api_1164":["Sec 15"],"awia":["AWWA Sec 1"],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.7","CBEST.10"],"tiber_eu":["TIBER.CLOSE","TIBER.REM"],"pci_hsm":["10"],"common_criteria":[],"isae_3402":["Clause 5","Clause 6","Clause 10"],"fca_sysc_13":["SYSC 13.5.3","SYSC 13.7.5","SYSC 13.G.3"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["00.a","00.c","04.b","06.c"],"iso_27799":["5.2","18.3"],"lloyds_ms":[],"naic_ds":["4","4E"],"nhs_dspt":["NDG-5.1","NDG-6.4"],"pra_ss1_23":["P4.5","P5.2"],"solvency_ii":["Art.46","Art.47"],"owasp_masvs_v2":[],"csa_ccm_v4":["AIS-03","SEF-05","TVM-09","TVM-10"],"csa_aicm":["AIS-03","SEF-05","TVM-09","TVM-10"],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.70","SCO60.71","SCO60.72","SCO60.82"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings extracted from framework-coverage data 2026-10-03: iso_27001_2022 5.3, 6.1 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: privacy baseline added, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-018","SP-043"]}}