Skip to content
Notifications
Clear all

Thoughts on the 'software security posture' score? Useful or vanity metric?

4 Posts
4 Users
0 Reactions
0 Views
(@carolp)
Reputable Member
Joined: 3 weeks ago
Posts: 196
Topic starter   [#24407]

Just got rolled into our dashboard. The "software security posture" score. It's an aggregate of scan results, policy compliance, etc.

Is anyone actually using this to drive decisions, or is it just another CISO dashboard vanity metric? I can see it being useful for:
* Tracking trend over time across many projects.
* A single number for non-technical stakeholder reports.

But I'm skeptical. Does a "good" score mean you're actually secure, or just that you're good at passing Veracode's specific scans? Could incentivize gaming the system over real fixes.

What's your take? Useful KPI or noise?


—cp


   
Quote
(@davids)
Reputable Member
Joined: 3 weeks ago
Posts: 272
 

I've seen these scores become genuinely useful, but only when teams treat them as a conversation starter, not a final grade. The risk you pointed out about gaming the system is real. I've watched teams prioritize quick-fix, low-hanging fruit to bump the number while a critical but complex vulnerability stays open.

So its value depends entirely on what you do after you see the number. Do you dive into why a score dropped 5 points on Project X this month, or do you just celebrate a green arrow going up? The former leads to action, the latter is just decoration for a slide.

Has your team discussed what a meaningful change in the score would actually trigger? That's often the missing piece.


Stay curious, stay critical.


   
ReplyQuote
 danf
(@danf)
Estimable Member
Joined: 3 weeks ago
Posts: 72
 

You're right to be skeptical. That single number for non-technical stakeholders is its primary, and maybe only, genuine use. It lets you say "see, it's going up" in a board meeting.

The real problem is your second question. A "good" score absolutely means you're good at passing that specific vendor's scans, full stop. It tells you nothing about your exposure to a novel attack vector or a misconfiguration their tool doesn't cover. It measures your compliance with their checklist, not your security.

It becomes noise the moment someone tries to use it as a root-cause metric. A drop of 5 points could be one critical bug or fifty low-severity style guide violations. Chasing the number will absolutely optimize for the latter.


Anecdotes aren't data.


   
ReplyQuote
(@cloud_ops_learner_99)
Reputable Member
Joined: 2 months ago
Posts: 254
 

Yeah, that "passing the vendor's scans" part hits home. I saw something similar when our team got flagged for "security findings" that were basically Terraform formatting issues in a module's outputs. Fixed the indentation, score went up, but did anything actually get more secure? Nope.

It feels like a compliance checkbox, not a real security measure. Maybe the only safe way to use it is as a rough, high-level trend indicator? Even then, like you said, it could drop for trivial stuff.



   
ReplyQuote