Abstract: To solve the question of how to evaluate the performance of information security management, this paper, directed by the criterion GB17859 and ISO/IEC17799, explores one kind of method of security management metrics based on AHP model, and makes the emphasis on how to decide the weight of two kinds of metric elements. Keywords: Information Security, Security Management Metrics, Analytic Hierarchy Process