Stop Using Vulnerability Counts to Measure Software Security.
This article argues that counting fixed vulnerabilities is a misleading measure of software security, as it ignores the context, effort, and process improvements behind each fix. Vulnerabilities are discovered under varying conditions, influenced by factors such as tool advances, human diligence, an...
| Publicado en: | Communications of the ACM Vol. 68; no. 9; pp. 34 - 37 |
|---|---|
| Autores principales: | , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Sep2025
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |