eamondawes (Community Member) asked a question.

Best Practices for securing Dynamic Analyses

What are the best practices for securing Dynamic Analyses? For Applications, if you are not a Creator, you cannot change the visibility of an Application, but that same distinction doesn't exist in Dynamic Scans. If there is a user in both team A and B, they can edit Dynamic Analysis A to allow members from team B. Someone from team B can now unlink Analysis A from Application A and then link it to Application B. This is a security hole and occurs whenever someone is part of more that one group.

 

Are there better roles to use? How do your teams secure their dynamic scans? What paradigms do you follow?


  • Eamon,

     

    Thank you for your question. Dynamic Analysis handles multiple use cases, requiring different permissions when compared with application profile. We have reused the existing Veracode Platform roles and assigned permissions in Dynamic Analysis.

     

    When it came to linking to applications, we released a feature called app linking to link a URL to an application profile. We had tighter restrictions around what the user roles could do in Dynamic Analysis, in particular creator and submitter. We received consistent feedback from several customers (Security Leads) that creator and submitter need to be able to link to applications and also unlink. In other words, these users should be autonomous and be able to configure, schedule, kick off, evaluate policy and review reports without asking for assistance from the Security Lead. In addition they had to unlink from an application profile and relink to a different profile. We have since added app linking and unlinking permissions to creator and submitter and this has provided a smoother workflow for majority of our customers.

     

    I agree that additional security measure between teams can be implemented. The best way to proceed is to further understand your use case and brainstorm on how best to achieve this without complicating the user interface.

     

    Thanks,

    Bhavna Sarathy

    Expand Post
  • eamondawes (Community Member)

    Thanks Bhavna, I can understand why application linking needed to be given. We've worked out a good solution for permissions, but it would be nice to have only creators able to change visibility and other more traditional "admin" functionality. on projects.

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.