KPI for Measuring of Security vulnerability density per line of code posted in category IT Security

WinningKPI - IT Security - KPI for Measuring of Security vulnerability density per line of code posted in category IT Security Oana Boteanu This indicator is for measuring the number of security vulnerabilities encountered per line of code. This is calculated by dividing the total security vulnerabilities found per software, by the total lines of code.
This is a key indicator for the security performance of a system, and several tests are run to achieve this figure. The aim of the software company is to minimise this KPI via different practices and systems (antivirus, antispyware, firewall etc)

Formula:
Total number of vulnerabilities/ Total lines of code

KPI Unit: number

KPI Time Frame: update monthly

Posted by Oana Boteanu | Help to protect community: Flag for moderation

Useful KPI? Download KPI as a .BSC project or start a web-based KPI project.

Ideas suggested by WinningKPI community:

Here are comments:

KPI Expert Example:

A company is measuring the number of security vulnerabilities encountered per line of code.

The formula is as below:
Total number of vulnerabilities/ Total lines of code

Total number of vulnerabilities found: 200
Total number of lines of code: 4000

Security Vulnerability Density per Line of Code:
200/4000 = 0.05 vulnerabilities per line of code

This resembles a ratio of one security vulnerability per every 20 lines of code.

Oana Boteanu | + | September 13, 2012 at 10:23 am

×

Have something to add? Have some more thoughts? Help others and earn 5 credits!

×

Sign in to comment Please, register (there is a button 'Become a member of WinningKPI community') in the right sidebar or sign in to leave comments. It is free and more - you will have scores for each comment you post.

Articles in IT Security category:

Relevant articles:

Become a member of WinningKPI community

Manage your KPIs with BSC Designer software

Random KPI requests: