DevSecOps Metrics and Continuous Improvement
1h 40mIntermediate2025-11-25
Authors

Tim Chase
Director of Application Security and Architecture at Nielsen
Course details
Join Tim Chase, the Global Field CISO at Orca Security, as he explores the integration of DevSecOps metrics for continuous improvement, emphasizing the need for a harmonized approach between development, security, and operations. Tim explains how to measure security performance using metrics like vulnerability detection rates and time-to-remediation, and how automation strengthens feedback loops for greater efficiency.
Along the way, Tim explores frameworks like DORA, SANS, and the NIST Cybersecurity Framework, reviewing practical strategies for integrating them into DevOps pipelines. With a focus on fostering collaboration and data-driven decision-making, this course shows how security metrics can guide remediation priorities, improve stakeholder communication, and optimize resource allocation—embedding security throughout the software development lifecycle.
Learning objectives
Identify and implement metrics that can be used to define success for DevSecOps
Explain key principles of data-driven decision-making in DevSecOps.
Develop strategies to prioritize remediation in DevSecOps using metrics.
Explain continuous improvement and why it is critical within DevSecOps.
Along the way, Tim explores frameworks like DORA, SANS, and the NIST Cybersecurity Framework, reviewing practical strategies for integrating them into DevOps pipelines. With a focus on fostering collaboration and data-driven decision-making, this course shows how security metrics can guide remediation priorities, improve stakeholder communication, and optimize resource allocation—embedding security throughout the software development lifecycle.
Learning objectives
Identify and implement metrics that can be used to define success for DevSecOps
Explain key principles of data-driven decision-making in DevSecOps.
Develop strategies to prioritize remediation in DevSecOps using metrics.
Explain continuous improvement and why it is critical within DevSecOps.
Concepts
Introduction
- DevSecOps metrics and CI
DevSecOps Metrics
- Adding security metrics to DevOps
- Security test coverage
- Mean time to detect (MTTD) vulnerabilities
- Mean time to remediate (MTTR) vulnerabilities
- Vulnerability density
- False positive rate of security tools
- Percentage of code scanned for security
- Compliance adherence rate
- Incident response time for security events
Measurement Frameworks
- DORA metrics framework
- SANS security metrics framework
- Flow framework
- NIST Cybersecurity Framework (CSF) metrics
- Selecting the right framework
- Practical tips for implementing frameworks in DevSecOps
Data-Driven Security Decision-Making
- Data-driven security decision-making in DevSecOps
- Learn abouting data-driven security decision-making
- Prioritizing remediation efforts with metrics
- Allocating resources effectively using metrics
- Communicating metrics to stakeholders for resource allocation
- Measuring long-term security outcomes
Continuous Improvement in DevSecOps
- Establishing a culture of continuous improvement
- Leveraging metrics for improvement
- Automating feedback loops in the pipeline
- Conducting post-incident reviews for learning
- Iterating on tooling and technology
- Upskilling teams for ongoing improvement
Conclusion
- Next steps
Related courses
- Building Your First DevSecOps Pipeline in AWS
- DevSecOps: Automated Security Testing
- DevSecOps: Building a Secure Continuous Delivery Pipeline
- Application Security in DevSecOps (2019)
- Application Security in DevSecOps
- DevOps Foundations: DevSecOps
- DevSecOps in Action: Securing and Governing Multicloud Infrastructures
- DevSecOps: Burning Questions
Related learn paths
- Develop Your Skills in Agile Software Development
- Getting Started with DevOps
- Impacting the Business as a Senior Manager or Leader
- Growing as a Sales Manager
- Get Ahead in DevSecOps
- Explore a Career in Application Security
- Infrastructure as Code with Terraform
- Getting Started with Continuous Integration / Continuous Delivery (CI/CD)