Initial Dynamic Analysis (DAST) Customer Onboarding
The Goal of Dynamic Analysis (DAST) onboarding is to complete the initial set up and alignment with your company’s risk program, as well as provide enablement workshops for your internal team to learn the product and integrate into your development toolchain.
Once this portion of your onboarding is complete, your team should have the tools necessary to teach your internal teams how to use this product. It is generally recommended to follow enablement topics numerically for each product unless you have prior security tool experience.
Below you will find the 6 enablement topics in the Initial DAST Onboarding Program:
| Workshop Name | Description | Avg Time | Desired Context | Required Attendees |
|
1. DAST Essentials Workflow
|
Demonstrate workflow for creating a web application scan including authentication, grouped URLs, seed URLs, etc.
|
30 mins
|
• Internet facing Web application
|
• Software Security
• Network Security
|
|
2. DAST Enterprise Mode Web App on Public Web
|
Demonstrate workflow for creating a web application scan including login script, crawl script, scheduling, etc..
|
30 mins
| • Internet facing Web application |
• Software Security
• Network Security
|
|
3. Dynamic Analysis of APIs on Public Web
|
Demonstrate workflow for creating a API scan including creating a API specification, authentication methods(SRM Scripts, etc..)
|
30 mins
|
• API Spec
• API Endpoint
|
• Software Security
• Network Security
|
|
4. Dynamic Analysis with ISM
|
Demonstrate workflow for creating a scan behind the firewall including gateway, endpoint management, proxies, etc.
|
30 mins
|
• Intranet facing Web application
|
• Software Security
• Network Security
|
|
5. Review Reporting and results management
|
Review results, mitigation workflow, and fix a finding
|
30 mins
| None |
• Software Security
• Developers
|
|
6. External Attack Surface Management Workflow
|
Demonstrate workflow for discovering external-facing digital assets and how to assess their security posture with DAST
|
30 mins
| None |
• Software Security
• Network Security
|
*This is not an exhaustive list and does not outline the full capabilities or features of our products as it relates to the integration into individual customer needs.
Topics (0)
Related Articles
Curl API commands do not support API Credentials for authentication 2.71KNumber of Views Forced Validation Paradigm 3.78KNumber of Views Grace Period in New Policy 970Number of Views Manual Penetration Test - Scheduling Process 1.62KNumber of Views App not in a state where new builds are allowed 4.98KNumber of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)