
Shuning, Veracode Community Manager (Veracode) asked a question.
Hello Community!
How are you using Veracode Analytics? As a SaaS-based platform, Veracode is in a unique position to give real-time feedback to your AppSec team with a ton of analytics! Veracode Analytics enables teams to pinpoint areas of success or needed improvement, saving your team valuable time and resources.
Share with your fellow members:
- Are you using custom or pre-built dashboards?
- What metrics are important to you?
- How are you implementing Analytics to influence AppSec behaviors ( for instance, How often are scans conducted? Which flaws are you focusing on? Which teams are most successful?)
⚡️ Resources: Setting up your dashboard for the first time? Check out Veracoders' takes on how to use pre-built dashboards, brought to you by @dhegelein (Veracode, Inc.) , @slusby (Veracode, Inc.).
.png)
We have a lot of custom dashboards- some of my favorite metrics right now are:
@ABacchi035478 (Community Member) Love the pipeline scan numbers metric - great way to further shift left; the least expensive flaws to fix are the flaws that are never written! Keep an eye out for Veracode expanding coverage to other languages in the near future. 😎
@Mark_M (Community Member) I had not thought about the 'thought remediated' metric; definitely a good way to check in on consistency of the code base! You learn something new every day.
Security Champion count/development personnel can give you a great idea if you have empowered enough champions to ensure security remains a priority (and your employees don't burn out!)
My number one rule is that "you get what you measure!" That is why I like policy compliance reports. If the groups are set up properly, then only one report is need for everyone from team members, managers, vp's and C-level. imho, providing that visibility to management will help keep a security mindset. It also could be used as a metric as part of a bonus or performance review.
@DeCaPa (Community Member) Analytics are a great way to communicate across departments and show stakeholders the health of the AppSec program! I have many customers that leverage analytics as part of their annual budget conversations... an added bonus is often colors and visuals can tell a better story than than a regular excel sheet. 📊
Another useful metric may be use (reuse) of built-in and custom cleansers. If the SAST scanner can report 'best practices' as it encounters the use of cleansers, we can then promote these as a rapid solution to common vulns, and cut down on all kinds of 'false positive' or unnecessary mitigation proposals.
You have me intrigued - I need to look into the cleansers more now thanks!