A Security Practices Evaluation Framework
Product Age
Description
Product age relates to both the availability of product knowledge as well as product refinement. An older product might be considered more stable with fewer defects, but there may be a lack of personnel or technology to support the system. Furthermore, making significant changes to a legacy system may be an extremely complex and laborious task. Working with a newer product may involve instituting complex elements of architectural design that may influence subsequent development, and may be prone to more defects since the product has not received extensive field use.
Data Collection
Determine the date of the first commit/first lines of code written. Record the number of months elapsed since that date. Record the age of the product in months.