Oh No! Security Metrics!
...critics (and most seasoned bugfinders) to do the work behind the scenes and they don't count those vulns
But in making this assertion, he's saying the vulnerabilities we remove (and do not add to the code in the first place) as part of the SDL process should be counted as though they were part of the product after we shipped it. We don't...
