Initial Static Analysis + Upload & Scan SCA Customer Onboarding
The Goal of Static Analysis + Upload & Scan SCA onboarding is to complete the initial set up and alignment with your company’s risk program, as well as provide enablement workshops for your internal team to learn the product and integrate into your development toolchain.
Once this portion of your onboarding is complete, your internal team should have the tools necessary to teach your internal teams how to use this product. It is generally recommended to follow enablement topics numerically for each product unless you have prior security tool experience.
Below you will find the 7 enablement topics in the Initial SAST Onboarding Program:
| Workshop Name | Description | Avg Time | Desired Context | Required Attendees |
|
1. App profile structuring
|
Discuss how customer application breaks down to collections, profiles, & sandboxes for SAST/SCA.
E.g. Discuss best practices for structuring software assets for scanning in Veracode (by software architecture, by programming languages, etc.)
|
30 mins
|
• App architecture(Monolith, Microservices, Mobile, Client-server, etc..)
• Programming Languages & Frameworks
|
• Software Security
• Developers
|
|
2. Policy Scan Enablement
|
Discuss scan workflow including scoping, packaging, & module selection
E.g. Successfully scan an prioritized application
|
30 mins
|
• Customer Application
|
• Software Security
• Developers
|
|
3. Veracode App Packaging
|
Discuss auto-packaging command on CLI tool and packaging cheat sheet
E.g. Focused conversation around optimizing input into our scanners for the highest quality of results
|
30 mins
|
• Customer Application
• Programming Language & Framework
|
• Software Security
• Developers
|
|
4. General overview of reporting and management of results
|
Review reporting features, mitigation workflow, and how to fix a finding
|
30 mins
|
None
|
• Software Security
• Developers
|
|
5. IDE Plug-ins (Veracode Authored)
|
Demonstrate IDE plug-in and how to start scans, review results, and mitigate flaws
|
30 mins
|
• Most utilized IDEs
• We will demo if available
|
• Software Security
• Developers
|
|
6. Automate scanning in Source Code Repo (Veracode Authored)
|
Demonstrate how to automate scanning from the repo with Veracode-authored plugins
|
1 Hr
|
• Most utilized Source Code Repo
• We will demo if available
|
• Software Security
• DevOps Engineer
|
|
7. Automate scanning in CI Build System (Veracode Authored)
|
Demonstrate how to automate scanning from the CI build system with Veracode-authored plugins
|
1 Hr
|
• Most utilized CI/CD Build System
• We will demo if available
|
• Software Security
• DevOps Engineer
|
*This is not an exhaustive list and does not outline the full capabilities or features of our products as it relates to the integration into individual customer needs.
Topics (0)
Related Articles
How to Fix a Veracode Static Analysis Flaw in 3rd-Party Software 6.01KNumber of Views Does Veracode's Dynamic Analysis support the scan of a Thick Client App? 387Number of Views Using an Allow-list in a Way Static Analysis can Detect 4.97KNumber of Views Grace Period in New Policy 971Number of Views How to Approach Remediation, What to Fix First? 2.47KNumber of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)