'How many vulnerabilities do we have?' is the most-asked and least-useful question in AppSec. The number moves when the scanner updates its rules, when a big repo is onboarded, when a feed has an outage — none of which say anything about your program. The durable questions are about the machine, not the weather.

Four metrics worth reporting

  • Coverage: eligible pipelines and repositories actually enrolled in scanning — with the denominator stated.
  • Enforcement: share of enrolled pipelines where policy actively gates builds versus monitor-only.
  • Drift: how often intended state diverged from observed state, and time-to-repair.
  • Freshness: age of the posture data every decision and dashboard reads from.

Why these survive scrutiny

Each metric has a controllable denominator and an owner. Coverage can be driven to a target; enforcement expresses risk appetite explicitly; drift measures operational integrity; freshness bounds how wrong you can be. An auditor can verify all four from records — if records exist.

Getting them without a spreadsheet farm

These metrics fall directly out of a control plane that already holds the inventory, the enrollment state, the sync results, and the audit history. In Kangl, coverage and enforcement are queries over managed-pipeline state, drift comes from the reconciliation loop, and freshness is tracked per posture sync — no quarterly manual census required.

KEEP READING