Problem
This is firewall and network security
a) Why are metrics important to an information/cyber security program, or why do you think metrics are not important to an information/cyber security program?
b) Why do you believe or not believe that the "Goal Question Metric" approach can be useful in developing metrics for an information/cyber security program even though the approach comes from the software engineering discipline?
c) Why do you believe some organizations fail at implementing useful metrics?