What's included in your dashboard?

Hello Community!

 

How are you using Veracode Analytics? As a SaaS-based platform, Veracode is in a unique position to give real-time feedback to your AppSec team with a ton of analytics! Veracode Analytics enables teams to pinpoint areas of success or needed improvement, saving your team valuable time and resources.

 

Share with your fellow members:

  • Are you using custom or pre-built dashboards?
  • What metrics are important to you?
  • How are you implementing Analytics to influence AppSec behaviors ( for instance, How often are scans conducted? Which flaws are you focusing on? Which teams are most successful?)

 

⚡️ Resources: Setting up your dashboard for the first time? Check out Veracoders' takes on how to use pre-built dashboards, brought to you by @dhegelein (Veracode, Inc.)​ , @slusby (Veracode, Inc.)​.


  • ABacchi035478 (Community Member)

    We have a lot of custom dashboards- some of my favorite metrics right now are:

    • Pipeline scan numbers by month- we are just getting into using the pipeline scanner and I want to understand how much its being used by our teams.
    • Static scans by month- with a year trailing- we want to be able to see the ramp-up of where we have started and what it looks like a year from then, and the results are drastic after we are instituting automation and self service for our teams.

     

    Expand Post
    • dhegelein (Veracode, Inc.)

      @ABacchi035478 (Community Member)​ Love the pipeline scan numbers metric - great way to further shift left; the least expensive flaws to fix are the flaws that are never written! Keep an eye out for Veracode expanding coverage to other languages in the near future. 😎

  • Mark_M (Community Member)

    • Average Time to Remediate a specific type or class of defects (XSS, SQLi, weak ciphers, etc.)
    • Frequency of defects thought remediated popping back up in scans - a frequency analysis of defect types. If they begin high then get knocked down, but start going back up, something changed in the environment and should be investigated.
    • Security Champion count/development personnel (all team members) - tells you the density of Sec Champs available to development teams.

     

    Expand Post
    • dhegelein (Veracode, Inc.)

      @Mark_M (Community Member)​ I had not thought about the 'thought remediated' metric; definitely a good way to check in on consistency of the code base! You learn something new every day.

       

      Security Champion count/development personnel can give you a great idea if you have empowered enough champions to ensure security remains a priority (and your employees don't burn out!)

      Expand Post
  • DeCaPa (Community Member)

    My number one rule is that "you get what you measure!" That is why I like policy compliance reports. If the groups are set up properly, then only one report is need for everyone from team members, managers, vp's and C-level. imho, providing that visibility to management will help keep a security mindset. It also could be used as a metric as part of a bonus or performance review.

    • dhegelein (Veracode, Inc.)

      @DeCaPa (Community Member)​ Analytics are a great way to communicate across departments and show stakeholders the health of the AppSec program! I have many customers that leverage analytics as part of their annual budget conversations... an added bonus is often colors and visuals can tell a better story than than a regular excel sheet. 📊

  • Mark_M (Community Member)

    Another useful metric may be use (reuse) of built-in and custom cleansers. If the SAST scanner can report 'best practices' as it encounters the use of cleansers, we can then promote these as a rapid solution to common vulns, and cut down on all kinds of 'false positive' or unnecessary mitigation proposals.

    • ABacchi035478 (Community Member)

      You have me intrigued - I need to look into the cleansers more now thanks!

Topics (5)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.