You cannot improve what you do not measure: A triangulation study of software security metrics
Arina Kudriavtseva, Olga Gadyatskaya · 2024
When organizations invest in security, they need to monitor if their security program is effective and helps them remediate vulnerabilities. For this purpose, many organizations collect security metrics. In this paper, we investigate the current state-of-the-art and state-of-practice of security metrics used to measure security across all phases of software development lifecycle (SDLC). The study focused on gaining multiple perspectives on software security measurement. To this end, we performed a triangulation study that compared security metrics proposed in the academic literature, metrics mentioned in grey literature aimed at software practitioners, and metrics elicited in a focus group workshop with secure software engineering experts.