Intrusion Detection System is an integral component of the computer security infrastructure. It is usually put in place to detect computer security policy violations. While its role is important, its effectiveness is not easily measurable. This paper proposes a framework for assessing how well a rule-based Intrusion Detection System is performing its intended task.