Reputation: 751
How does fortify calculates the estimated remediation effort score?
In the page 129 of this document, the product manual says what the score is, what it means, but it does not provide any clue on how it's calculated.
Upvotes: 0
Views: 75
Reputation: 1
"Estimated Remediation Effort" score is a metric to provide developers and security analysts with an approximation of the time and effort required to address and remediate a security finding or vulnerability identified by the tool.
You can use general principles to calculate it:
Fortify probably uses a database of historical data or defined estimates to assign an initial time required for various vulnerabilities.
Systems improve their estimates by feedback from users on the accuracy of previous estimates and historical data on actual remediation times.
Upvotes: 0