I see very few organizations 'measuring' software quality/robustness in any but the most simplistic way (lines of code - SLOC), even though the Chidamber/Kemmerer Object-Oriented Metrics calculations are available in many of the toolsets now.

Software security metrics could easily be incorporated into a larger effort at increasing the sophistication of software measurement.

Forg Snud

From the Art of War:
"If his forces are united, separate them....

We can form a single united body, while the enemy must split up into fractions. Hence there will be a whole pitted against separate parts of a whole, which means that we shall be many to the enemy's few."

Of course just who the enemy is here might be up for debate.

