Federal Agency Security Practices (FASP)
This is an interesting site, with best practices, security awareness briefings and checklists for setting up systems.
There's a
very interesting section on this page, that has material by Marianne Swanson et al on security metrics. She's the co-author of "SP 800-55 Security Metrics Guide for Information Technology Systems", which among other documents can be retrieved at
http://csrc.nist.gov/publications/nistpubs/index.html - I found here materials very thought-provoking, please have a look.