# Governance in DevSecOps: Measuring and Improving Security Outcomes

DevFeed: [Governance in DevSecOps: Measuring and Improving Security Outcomes](<https://devfeed.tech/articles/governance-in-devsecops-measuring-and-improving-security-outcomes-7946.md>)

Original publisher: [Read original article](<https://snyk.io/blog/governance-in-devsecops-measuring-improving-security-outcomes/>)

Author: Ben Desjardins

Published: 2025-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [governance](<https://devfeed.tech/tags/governance.md>), [measurement](<https://devfeed.tech/tags/measurement.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [testing](<https://devfeed.tech/tags/testing.md>)

## AI overview

This article explains how governance and measurement strengthen DevSecOps and application security programs. It describes using risk-based metrics and KPIs--including open issue backlog, issue aging, MTTR, SLAs, and testing rates in IDEs, CLIs, and CI/CD pipelines--to benchmark current security posture, guide strategy, verify remediation, reduce risk, and accelerate development.

## Source excerpt

Learn how governance in DevSecOps helps improve security outcomes by measuring risk, optimizing processes, and aligning security efforts with business goals.