How does an ISMS provide information security metrics?
An ISMS provides the structure and context to produce metrics (i.e. gather metric data, extract information, and provide strategic intelligence). The idea of data/info/intelligence is VERY powerful when discussing metrics that matter. Also, this process based approach, when applied to an operational area, gives the guidance needed to understand what data to capture since a process by definition has a critical success factor, and key performance indicator. The KPI tells us what data (metric) to capture.