I want to start measure the software security, meaning that, I want to understand if my application is secure or not and improve from month to month.
It would be also really useful to have some suggestion of the tools.
I use sonar for detecting the vulnerabilities but it is not enough, because I am not able to see the progress and effort spend on it. For example, I can see I have 10 major vulnerabilities but I am not sure what can I measure instead of number of vulnerabilities