Code Review Metrics

Revision as of 11:05, 28 May 2008 by EoinKeary (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search


The objective of code review is to detect development errors which may cause vulnerabilities and hence give rise to an exploit. Code review can also be used to measure the progress of a development team in their practice of secure application development. It can pinpoint areas where the development practice is weak, areas where secure development practice is strong and give a security practitioner the ability to address the root cause of the weaknesses within a developed solution.

Metrics can also be taken relating to the performance of the code reviewers and the accuracy of the review process.

Secure Development Metrics

  1. Fault Density
  2. Risk Density
  3. Defect correction rate

Review Process Metrics

  1. Inspection Rate
  2. Defect detection Rate