Главная
Study mode:
on
1
Intro
2
Agenda
3
Questions from executives
4
Why Metrics
5
Risk Management Objectives
6
Measurement vs Metric
7
Phases of Metrics
8
Defects
9
Bad Scenarios
10
Vanity Metrics
11
Metrics Without Context
12
Metrics With Executives
13
Risk Management
14
Policy Standards Outreach
15
Software Environment
16
Software Security Capabilities
17
Risk Tolerance
18
Coverage
Description:
Explore effective software security metrics in this 50-minute conference talk from AppSec California 2016. Learn techniques to change conversations with executives about software security, encouraging them to ask the right questions and receive answers demonstrating progress towards meaningful objectives. Discover a progression of software security capabilities and corresponding metrics for different maturity levels. Gain insights on developing key metrics for your unique software security program through a detailed example. Delve into topics such as risk management objectives, measurement vs. metrics, phases of metrics, defects, risk tolerance, and coverage. Benefit from Caroline Wong's expertise as a thought leader in security strategy, operations, and metrics, drawing from her experience at companies like Cigital, Symantec, Zynga, and eBay.

Software Security Metrics - Developing Key Indicators for Executives

OWASP Foundation
Add to list