This document discusses security metrics for assessing information security. It begins by explaining why security metrics are important for measuring the effectiveness of security programs and benchmarking security investments. It then categorizes metrics according to their level and type, such as strategic, management, and operational metrics. Examples are provided for each category and type, including process, network, software, and people security metrics. Common issues in generating metrics and critical elements like asset value, threats, and vulnerabilities are also addressed.