https://www.amazon.com/How-Measure-Anything-Cybersecurity-Ri...
I've never managed to make the effort to apply his ideas with much rigor but they are definitely appealing and possibly better than the alternative of "maybe nothing".
https://www.amazon.com/How-Measure-Anything-Cybersecurity-Ri...