Expert Advice Community

Guest

Secure development KPIs

  Quote
Guest
Guest user Created:   Sep 21, 2018 Last commented:   Sep 21, 2018

Secure development KPIs

Thank you for all your advise - wondering if you can share some thoughts around KPI's to measure compliance with a secure development policy - practical tips only please, any reports you can think of Infosec can ask for - scenario is agile/ devops?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 21, 2018

Answer:

The most used KPIs to measure compliance with a policy are the result of audits (internal and external), regarding the number of non conformities identified, and the number of incidents which can be related to that policy.
It is important to note that measuring compliance means to do what is written, but you should also be concerned with the achieved results of what is done. For example, if your secure development police defines you have to perform periodic tests, if you perform the tests then your are compliant with the policy, but if the tests results frequently show a high number of failures, then your development process may have a problem that must be handled. Most often KPIs related to secure development process are the numbers or relevant risks treated by security controls imple mented in the software, and number of failures or vulnerabilities identified per test.

This article will provide you further explanation about KPIs:
- Key performance indicators for an ISO 27001 ISMS https://advisera.com/27001academy/blog/2016/02/01/key-performance-indicators-for-an-iso-27001-isms/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 21, 2018

Sep 21, 2018

Suggested Topics

Igor Created:   Mar 17, 2025 ISO 27001 & 22301
Replies: 0
0 0

Secure Development policy

Guest user Created:   May 11, 2023 ISO 27001 & 22301
Replies: 1
0 0

Secure development policy

Guest user Created:   Feb 26, 2023 ISO 27001 & 22301
Replies: 1
0 0

Secure coding