Leadership asks whether mandatory SAST gates actually improve outcomes for city applications. What should AppSec measure?
Select an answer to reveal the explanation.
Short Explanation
A gate that nobody measures is just a speed bump with a fancy name. Track whether fewer nasty bugs slip into production after SAST becomes mandatory. If escaped defects do not drop, fix the gate—not the slide deck.
Full Explanation
Assessing software security control effectiveness requires outcome-oriented metrics, such as trends in defects that escape to production despite pipeline gates. Counting tool runs alone does not prove risk reduction. Organizations should evaluate whether SAST and related controls correlate with fewer high-severity escapes and faster remediation.