DevSecOps leaders say security has done a lousy job making AppSec risks visible to developers. Traditional cybersecurity practices are not providing the kind of feedback to developers that helps them figure out how to make changes in their daily work that will actually reduce AppSec risk. The best risk leaders make their case by finding the right metrics to tell their story, says Mastercard’s Anna Marie Zettlemoyer. At Target, the security team developed what the company calls the Product Intelligence score, which wraps in data from its vulnerability databases and GRC tooling.”]

