What are the metrics in your executive dashboard?

Hi Community!

 

My name is Erica.  I’m a Security Program Manager and I’m responsible for helping customers plan and manage their AppSec goals, develop and share best practices, and provide reporting to management and internal stakeholders on program initiatives. Throughout my time at Veracode I’ve found a true passion working with our analytics team and am excited to reach out to all this week!

 

There is so much value in providing the right analytics to the right audience. As @DeCaPa (Community Member)​ and a few members pointed out in another discussion on AppSec metrics to begin with, a question that the C-level ultimately care about is largely -- "how secure we are”-- among other operational, tactical metrics that measures progress against that ultimate goal.

 

The two biggest compliments I've received when presenting metrics to a C-level was them saying, "now this shows me it's working" and the other was actually getting stopped so they could ask another team member to call X to see why application X hadn't fixed their flaws. Not only did that team fix their flaws in record speed, it stressed the importance of showing the right metrics to the right audience.

 

In assisting customers to create dashboards for executive view, here are three metrics that I often suggest my customers to consider:

 

  • Security Debt: Are teams keeping up with new flaws being found but also the backlog of existing open vulnerabilities that still need attention?
  • Fix Rate and Time to Fix: How fast teams are teams reacting to high severity findings and is the time to remediate improving over time
  • Industry Comparison: How are we doing against our peers?

 

Do these metrics resonate with your exec dashboards? What are the metrics that you shared with your exec team and why?


Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.