Links

Security Metrics

Severity Statistic

Based on verified issues

WRT

LInk to OWASP presentation from HP
And simply set your risk appetite, based on the least vulnerable product
Fill questionnaires for every product
Get better understanding on what's actually is risky

SLA

Control your SLA's in simple way
SLA for triage team
SLA for product team
​