# PM-06 Measures of Performance

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: Develop, monitor, and report on the results of information security and privacy measures of performance.
Guidance: Measures of performance are outcome-based metrics used by an organization to measure the effectiveness or efficiency of the information security and privacy programs and the controls employed in support of the program. To facilitate security and privacy risk management, organizations consider aligning measures of performance with the organizational risk tolerance as defined in the risk management strategy.

## Patterns that use it (2)
- Critical (1): SP-043 Security Metrics and Measurement
- Important (1): SP-018 Information Security Management System

## Clauses by framework (51 frameworks)
- iso_27001_2022: 4.4, 5.3, 6.1, 6.2, 9.1, 9.3, 10.1, A.5.35, A.5.36. OSA's own, not in NIST's crosswalk: 4.4, 9.3, 10.1, A.5.35, A.5.36
- iso_27002_2022: 5.35, 5.36
- cobit_2019: APO13, EDM02, MEA01, MEA02
- pci_dss_v4: 12.4
- nist_csf_2: GV.OV-01, GV.OV-03, ID.IM-01, ID.IM-03. OSA's own, not in NIST's crosswalk: GV.OV-01, ID.IM-01, ID.IM-03
- nis2: Art. 21(2)(f), Art. 32
- apra_cps_234: Para 27-28
- pra_op_resilience: SS1/21-6.2, SS1/21-7.1
- bsi_grundschutz: ISMS.1
- bio2: 5.35, 5.36
- rbi_csf: Annex1.21, ITGRCA.21
- fisc: FISC.O7
- lgpd_bcb: BCB.Art.18, BCB.Art.19
- hkma_tme1: TME1.3.3, TME1.12.3
- dnb_good_practice: DNB.5.2, DNB.14.1, DNB.16.2, DNB.16.4
- cbb_tm: TM-16
- cbuae: CR-14
- nca_ecc: 1-2, 1-7, 1-8
- qatar_nia: GV
- sama_csf: 1.3, 1.9, 2.2
- uae_ia: T1
- bog_cisd: CISD-COMP, CISD-IV
- bom_ctrm: 1.5, 5.4
- cbe_csf: GOV-3
- cbn_csf: Part2.2, Part6.1, Part6.2, Part7.2
- sa_js2: JS2-5, JS2-9
- bcbs_239: Principle 12
- eba_ict: 3.3.5
- ffiec_is: Appendix A, II.C.1, II.C.4, II.D, IV.A, IV.A.1, IV.A.4
- hipaa_sr: §164.308(a)(8)
- nydfs_500: 500.2
- sebi_cscrf: AUDIT, CCI, GV.OV
- cmmc_2: CA
- nrc_73_54: 73.54(d)
- doe_c2m2: PROGRAM
- api_1164: Sec 15
- awia: AWWA Sec 1
- cbest: CBEST.7, CBEST.10
- tiber_eu: TIBER.CLOSE, TIBER.REM
- pci_hsm: 10
- isae_3402: Clause 5, Clause 6, Clause 10
- fca_sysc_13: SYSC 13.5.3, SYSC 13.7.5, SYSC 13.G.3
- hitrust_csf: 00.a, 00.c, 04.b, 06.c
- iso_27799: 5.2, 18.3
- naic_ds: 4, 4E
- nhs_dspt: NDG-5.1, NDG-6.4
- pra_ss1_23: P4.5, P5.2
- solvency_ii: Art.46, Art.47
- csa_ccm_v4: AIS-03, SEF-05, TVM-09, TVM-10
- csa_aicm: AIS-03, SEF-05, TVM-09, TVM-10
- basel_sco60: SCO60.70, SCO60.71, SCO60.72, SCO60.82
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-06
- Clauses only: /api/v1/controls/PM-06?fields=mappings
- Page for people: /controls/pm-06/
