Which metric is most meaningful when reporting application security program effectiveness to a CISO?
-
A
Number of lines of code scanned
-
B
Mean time to remediate critical vulnerabilities
-
C
Total number of SAST tool alerts generated
-
D
Number of security engineers on the team