
Sign up to save your podcasts
Or


We can create top 10 lists and we can count vulns that we find with scanners and pen tests, but those aren't effective metrics for understanding and improving an appsec program. So, what should we focus on? How do we avoid the trap of focusing on the metrics that are easy to gather and shift to metrics that have clear ways that teams can influence them?
Segment resources
- https://www.philvenables.com/post/10-fundamental-but-really-hard-security-metrics
- https://cloud.google.com/blog/products/devops-sre/using-the-four-keys-to-measure-your-devops-performance
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw193
By Security Weekly Productions4.8
44 ratings
We can create top 10 lists and we can count vulns that we find with scanners and pen tests, but those aren't effective metrics for understanding and improving an appsec program. So, what should we focus on? How do we avoid the trap of focusing on the metrics that are easy to gather and shift to metrics that have clear ways that teams can influence them?
Segment resources
- https://www.philvenables.com/post/10-fundamental-but-really-hard-security-metrics
- https://cloud.google.com/blog/products/devops-sre/using-the-four-keys-to-measure-your-devops-performance
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw193

7,721 Listeners

370 Listeners

265 Listeners

374 Listeners

637 Listeners

1,022 Listeners

8,020 Listeners

174 Listeners

181 Listeners

314 Listeners

73 Listeners

57 Listeners

137 Listeners

40 Listeners

45 Listeners