This document discusses developing useful metrics for governance, risk management, and compliance programs. It begins by explaining the difference between measures and metrics, and emphasizes tying metrics to business objectives and decisions. A 5-step GQIM process is introduced for deriving metrics from objectives: identifying goals, questions, indicators, and metrics based on objectives. Examples are provided for an incident management objective. The document also discusses challenges in identifying meaningful metrics and getting started with a measurement program by focusing on a few key business objectives and questions.