
Community Announcements — JBrazuelo (Community Member) asked a question.
Hello, anyone have a model of workflow of the process of evaluatión of a application ?

Community Announcements — JBrazuelo (Community Member) asked a question.
Hello, anyone have a model of workflow of the process of evaluatión of a application ?
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the community.
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
.png)
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
Hi @JBrazuelo (Community Member) - thank you for your question! Just a reminders 🙂 -- The Community Exchange is for Community news, updates, and announcements; for product related questions, you can use any Ask The Community button to post your question or post it in a discussion forum ("Discussions" from the top navigation).
I think this is an excellent topic for discussion. While i'm not sure if it is meant w/in the context of Veracode, or a process model in general, both should be similar. If the latter, perhaps OWASP has a best practice? In any case, @Shuning, Veracode Community Manager (Veracode) - is it possible to move this discussion to the location you mention, with hopes it gets more input? -thanks
Thanks @DeCaPa (Community Member) for raising this topic for discussion. I will move this thread to the #Program Management board. I am also connecting with folks who may have insights into this topic.
Hello,
I believe you’re asking, what are the typical phases within the SSDLC flow at which to execute a security scan? If so – going left to right, here are some phases/steps, along with the type of security evaluation that can typically be done at particular points in parenthesis:
1. Design (application threat modeling)
2. IDE Code (SAST IDE scanning, i.e. Greenlight)
3. Source Check-in (SAST Pipeline scanning, sandbox scanning)
4. Code integration (SAST Sandbox scanning)
5. Verification/testing (SAST policy scanning; Integration scanning (IAST), DAST)
6. Deploy (DAST)
7. Maintain (DAST, Penetration Testing)
You’ll notice there’s some overlap with some scan types across multiple steps/phases. Two general guidelines are:
1. Scan often (i.e. SAST in multiple phases is not necessarily a waste – early scans may run faster, and later scans may be more thorough)
2. Scan early (i.e. the soonest you can scan, find flaws, and address – the faster you’ll converge on truly secure deployment package).