article thumbnail

Challenging ROI Myths Of Static Application Security Testing (SAST)

ForAllSecure

Some of the industry’s best SAST checkers are designed to have FP rates below 5%, but if we use a common metric of 15-50 errors per 1KLoC as posited in Steve McConnell’s Code C omplete , the number of potential defects identified by SAST on that 10MLoC is approximately 150k-500k defects! Why is this important?

article thumbnail

Challenging ROI Myths Of Static Application Security Testing (SAST)

ForAllSecure

Some of the industry’s best SAST checkers are designed to have FP rates below 5%, but if we use a common metric of 15-50 errors per 1KLoC as posited in Steve McConnell’s Code Complete , the number of potential defects identified by SAST on that 10MLoC is approximately 150k-500k defects! Why is this important?

article thumbnail

Challenging ROI Myths Of Static Application Security Testing (SAST)

ForAllSecure

Some of the industry’s best SAST checkers are designed to have FP rates below 5%, but if we use a common metric of 15-50 errors per 1KLoC as posited in Steve McConnell’s Code Complete , the number of potential defects identified by SAST on that 10MLoC is approximately 150k-500k defects! Why is this important?