Metrics for Security Testing Programs
What metrics best capture the progress of Enterprise-wide Security Testing programs? Here are four of our favorites:
1. Number of Apps tested

This shows how quickly the enterprise’s apps are enrolled in the testing program. Keep track of both the number of apps tested, as well as the number of tests done each month. The first should grow continuously until all apps are enrolled for testing. The second shows the level of testing activity - expect it to rise sharply initially and then stay at a lower rate once most apps complete 2 rounds of testing.
2. Apps with High Risk Findings

What fraction of the apps tested have high risk findings? This gives top management a high level view of how secure the enterprise’s applications are. In the early days of any application security program, the red line will closely follow the blue. As fixes are implemented, and development practices are improved, the red starts dropping off. The goal of course, is to send that red line to zero.
3. Findings per Application

The average number of findings is another high level metric. Recorded over time, it tells you how rapidly the organization is tightening application security. The drop in the first 6-12 months after a testing program is initiated usually come from fixing the holes discovered in testing. After that, the drops usually come from more fundamental improvements in the software development process.
4. Number of Findings Closed

This tells you the rate at which developers are fixing security bugs - steeper the curve, the better it is. Management should question what’s going on if those bars drop in any month (like in October in the sample graph).
Plynt provides penetration testing and code review services to clients worldwide. If you are interested, please contact us for a quote. We’ll get back to you within one working day.Add yours.closed for this post.
Monthly Archives
- September 2008
- August 2008
- July 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007
- April 2007
- March 2007
- February 2007
- January 2007
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
Syndication
You can read full entries of Palisade Blog using an RSS reader. Use this link —



