It would have been nice to see suggestions for each metric mentioned on:
1. How to gather the data
2. How to verify the data
3. How to visualize the data
4. How to ensure repeatability
5. Determining whether or not it is to be displayed as quantitative or qualitative
A good article for a few metrics is:
http://www.csoonline.com/article/220462Also, Andrew Jaquith's book Security Metrics is an excellent read if you have to develop any type of metric.