Your 30/60/90 Day Plan
Veracode’s approach to AppSec governance centers on a partnership that helps you achieve a world-class program, not a disparate set of tools. A key aspect of this partnership is defining a 30-60-90 day timeline, a process proven to ensure success.
So what does this process look like? Obviously, the needs and goals vary from customer to customer, but practices are the following:
First 30 Days
- Identify and prioritize applications/languages: Which applications require security coverage and need to be scanned? What are the languages of those applications? Leverage our compilation guide for instructions on how to properly upload your code.
- Create a reporting structure: Identify key stakeholders (“Security Champions”) within the organization that will own the security program and work with your Security Program Manager on setting expectations/program goals.
- Train key members of the AppSec team (Administrator, Security Lead, Development Team).
- Define policy mandate: The“Security Champion” on the team will help implement and govern the defined policy within the platform. In successful programs, this role will act as Mitigation Approver to help review, approve, and accept the risk of the development team’s proposed mitigations.
- Create platform policy: Policies are standards you will hold your applications to. Work with your Security Program Manager to identify concrete goals of the program -- this exercise will help in creating a policy best suited to your applications. For example, HIPAA compliance, PCI compliance, or OWASP Top 10 are examples of third-party security standards that can help form the basis of a policy mandate.
- Define what success looks like for you: Identify concrete metrics to track progress against your goals. Here are some examples:
Pro tip: Use these metrics to work with your Security Program Manager on defining a policy that best fits your program’s needs.
60 Days
- Engage development teams: It’s key to engage your dev team early! Get the Veracode Community’s best practices for helping security & development teams to work together most effectively.
- Onboard developers: Encourage developers to sign up for product demos with live Q&A led by the Veracode support engineers, and deliver onboarding training to developers.
- Baseline application scans within the platform: Begin regular scanning and regular check-ins with the dev team.
90 Days
- Establish a baseline: Encourage the dev team to start submitting consultation requests. (Learn more about what a consultation call is and how to schedule one.) Start to deliver onboarding training to the next group of application teams.
- Initiate integrations: Set up integrations using Veracode plugins or APIs -- check out all available plugins and APIs.
- 90-day program internal review: By the time you hit the 90-day mark of your program, it’s helpful to gather your security and development teams and review your progress together. Some areas to look at:
- Onboarding: Any dev team that needs to be onboarded?
- Applications: Any new apps that need to be scanned?
- Policy: Any policy that needs to be changed? It’s time to grow out of out-of-the-box policy and start customizing your own.
- Remediation timeframe: Based on the remediation timeline over the last three months, you should now have enough data to adjust the default grace period to keep up with your remediation timeframe. (Extend if your team needs more time, shorten if your team has been getting ahead of it.)
- 90-day check-in with your security program manager: It’s likely that you may have questions coming out of the 90-day program review. Schedule a call with your Security Program Manager who can help benchmark your progress against similar organizations and, based on where you are, suggest the next steps.
Have a question?
Ask our Community of Veracode product experts and AppSec leaders.
.png)