
Tim J (Veracode PM) (Veracode) asked a question.
Hello 👋 , Veracode PM @Tim J (Veracode PM) (Veracode) here. We wanted to give everyone advance notice of an important change we'll be making to the security standards in the Veracode Policy Manager in the June 2020 Veracode Platform release, currently planned for the end of June. This release will update the SANS Top 25 security standard to the 2019 CWE Top 25 security standard.
In most cases this will not affect your applications unless you update your policies, because the new 2019 CWE Top 25 standard is being added as a new rule. You can choose to incorporate this rule at your own cadence.
However, if your policy uses the PCI Security Standard rule or the PCI 3.2.1 policy, the policy will automatically reflect the new 2019 CWE Top 25, since most PCI assessments will reflect the new standard. In some cases, this means that applications previously passing policy will fail the next time it is scanned.
If you have questions about the change and about whether your applications are affected, please first check your policies to see if you are using a PCI security standard rule – only a few customers include this directly in their policies. If you have further questions, please contact your Veracode security program manager for further assistance.
.png)