owaspsamm / samm-suite

This is an issues-only repository.
0 stars 1 forks source link

Revisit the Measure and Improve L1 requirement for 3 metrics categories #64

Open aramhovsepyan opened 1 day ago

aramhovsepyan commented 1 day ago

Description: Currently Measure and Improve requires 3 metric categories: effort, result and environment. However the contribution of these metrics towards lowering the security risk is not given. For example, effort metrics mention training hours though the number of training hours is not necessarily a good proxy for security awareness.

Acceptance criteria: