• Hi @JBrazuelo (Community Member)​ - thank you for your question! Just a reminders 🙂 -- The Community Exchange is for Community news, updates, and announcements; for product related questions, you can use any Ask The Community button to post your question or post it in a discussion forum ("Discussions" from the top navigation).

  • DeCaPa (Community Member)

    I think this is an excellent topic for discussion. While i'm not sure if it is meant w/in the context of Veracode, or a process model in general, both should be similar. If the latter, perhaps OWASP has a best practice? In any case, @Shuning, Veracode Community Manager (Veracode)​  - is it possible to move this discussion to the location you mention, with hopes it gets more input? -thanks

  • jmaski (Veracode, Inc.)

    Hello,

    I believe you’re asking, what are the typical phases within the SSDLC flow at which to execute a security scan? If so – going left to right, here are some phases/steps, along with the type of security evaluation that can typically be done at particular points in parenthesis:

     

    1.     Design (application threat modeling)

    2.     IDE Code (SAST IDE scanning, i.e. Greenlight)

    3.     Source Check-in (SAST Pipeline scanning, sandbox scanning)

    4.     Code integration (SAST Sandbox scanning)

    5.     Verification/testing (SAST policy scanning; Integration scanning (IAST), DAST)

    6.     Deploy (DAST)

    7.     Maintain (DAST, Penetration Testing)

     

    You’ll notice there’s some overlap with some scan types across multiple steps/phases. Two general guidelines are:

    1.     Scan often (i.e. SAST in multiple phases is not necessarily a waste – early scans may run faster, and later scans may be more thorough)

    2.     Scan early (i.e. the soonest you can scan, find flaws, and address – the faster you’ll converge on truly secure deployment package).

     

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.