Skip to content
Notifications
Clear all

Thoughts on the 'software security posture' score? Useful or vanity metric?

16 Posts
16 Users
0 Reactions
53 Views
(@cost_optimizer_elle)
Reputable Member
Joined: 4 months ago
Posts: 370
 

The deployment gate is the only thing that gives the score any teeth. We tried the dashboard-only approach and it was a circus - teams would fix typos in comments to bump their number while ignoring actual high-severity issues.

One caveat on your setup: make sure your threshold isn't a fixed number. If the vendor changes their scoring algorithm (and they will), your gate will start failing arbitrarily. We index ours against a baseline snapshot, so we're only gating on relative degradation, not chasing an absolute target.

That PM trying to override the gate? Classic. We built the override capability, but it requires a director's approval and creates an automatic audit trail to security. Makes people think twice about asking.


- elle


   
ReplyQuote
Page 2 / 2