logo

Incorporating cost into appsec metrics for organisations

ID: e53f9b31-6f7b-538b-b772-20ca9ca0934c

STIX ID: report--e53f9b31-6f7b-538b-b772-20ca9ca0934c

Feed Name: SensePost Blog

Date Published: 2011-05-22

Date Updated: 2026-04-29

...
...

The document critiques common application security metrics that rely on vulnerability counts (e.g., DBIR, SOSS, WhiteHat, WASC) for lacking resolution and failing to account for attacker effort, and proposes a base metric of findings-per-day (or days-per-finding) to approximate attacker cost for improved decision-making, trend analysis, and peer comparisons. It acknowledges limitations (tester skill variance, differing app functionality, minimum sample sizes), suggests enriching data with contextual attributes (e.g., outsourcing, SDLC model, tech stack), and shares positive feedback from a client field test indicating the approach can support practical security decisions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.