Program metrics measure the effectiveness of governance processes and provide a basis for continuous improvement and informed decision-making. "Metrics are essential for evaluating governance performance, demonstrating effectiveness, and identifying areas for improvement." - CISM Review Manual 15th Edition, Chapter 1: Information Security Governance, Section: Monitoring and Metrics* ISACA's practice questions confirm that program metrics are key to evaluating governance effectiveness.