
Shuning, Veracode Community Manager (Veracode) asked a question.
Hello Community!
Whether you’re on the development or security side of the house, you probably have best practices or implementation/onboarding challenges to share. Whatever the challenge or triumph was, it will be really helpful for other members new to Veracode to hear your advice.
Need some inspiration on what to share? Here are some ideas:
- What was helpful in onboarding with Veracode?
- What was challenging/confusing when you first got started? How did you overcome it?
⚡️ Resources: Looking to implement Veracode, or in the middle of the implementation? Check out Your 30/60/90 Day Plan: How to Roll out an AppSec Program by @dhegelein (Veracode, Inc.) and @slusby (Veracode, Inc.).
Also check out the attachment, AppSec Best Practices vs Practicality
.png)
Reading through the 30/60/90 Day Plan, I couldn't agree more. I think it’s extremely important to identify and prioritize applications but I also think it might be even more important to have an understanding on how you would like to use Veracode at various levels of integration/on-boarding as well. My two additional suggestions might seem a little waterfally but bear with me:
1. Know how you want to interact with the Veracode Platform with early/half/full integration
Decide what you will want to use throughout various cycles of implementation and on-boarding.
Knowing/thinking about the answers to some of these scaling and on-boarding questions can drastically save you a lot of time and stress later by figuring out how much time will something take you now vs later. For example:
2. Create a repeatable and mandatory framework for on-boarding applications and users
After determining how you’ll want to interact with Veracode in the process, spend time to create a mandatory (preferably automated) framework based on your requirements. If it isn't mandatory then you'll have some applications/teams causing a backlog of work for you to fix later. Here are two of many possible examples:
TL;DR: Knowing how you’ll want to interact with Veracode at various steps in the process will help you prioritize which steps to automate first to have quick and consistent on-boarding of new teams/users/applications. This will allow your team to focus on vulnerabilities at both micro and macro levels rather than having to hand-hold teams/applications/users through the on-boarding process.
We use a request form for devs to request a new application profile. This allows us to capture all fields we need and reach out if they didn't include something important. Like you said its really annoying to get the the reporting phase only to find out that certain fields were left blank. I think data validation in the customizable metadata fields would be VERY helpful too.
What we found useful when onboarding new applications and teams to the Veracode Platform was a required data (metadata) collection form that provided us a single-stop for all information that we needed about the application and the team supporting it. We asked for the App ID from the Portfolio Management tool, the application name, development team manager name, Security Champion for the application or team, then each team member's information so we could create IDs for them and enroll them in Role-Based AppSec Training (if they had not already completed it) to make sure everyone was trained and certified to work on the application.
Once onboarded, we had a Wiki for the development teams -- on the Wiki platform they use daily -- to help them with the mechanics of packaging and uploading the application, along with a request form to our team if they wanted personal help so they were not left hanging out with remaining questions or confusion on what they needed to do. We did the same for Triaging scans or any other help they needed to become empowered to take on AppSec as a team and as developers on mission-critical applications.
We went through a few versions to the Onboarding Form, but once it had everything everyone on the AppSec needed, the form did not change again in 4+ years of use.
It looks like the question changed a bit, but that's OK - the new one needs answers too!
The BEST advice I would give to someone totally new to Veracode is to think of it as more of a developer's tool than a tool for the Security Group outside of scrum teams. In other words, if developers are convinced that it was developed for developers by developers to help make developers better at their jobs, the teams tend to embrace it and strive to use it, rather than being thought of something 'thrust' upon them by 'those guys' and use it as a checkbox activity. Don't let that happen to you!!
So you asked,
figuring out how to address all the flaws found, what was best practice for documenting mitigation for all the issues, once we met with the consultant many things cleared up, repeat flaws was frustrating, learning how modules uploaded worked, whether we had captured all the modules for code we developed. Getting a source code inventory was a challenge, I learned to work with the developers on the scan process and addressing flaws found, that was difficult at first but through experience now have a good process.
Schedule a meeting. Ask questions. Read the documentation.
Thank you @EGertis462759 (Community Member) for the advice! Which meeting (with which team at Veracode) did you most valuable? Also, which documentation would you recommend as a "must-read" for anyone who's beginning to implement Veracode?
Eric Noll is the best support engineer at Veracode. For a must read I would suggest starting here: https://help.veracode.com/r/t_working_with_java_wrapper. Get the scan set up. Use the product. Then extract value by using the prebuilt dashboards to communicate results. Set up e-learning to give developers the instruction needed to write secure code. The certification process requires these things anyways so it is very easy to communicate why we are doing this to senior management.
Software testing is the process of evaluating a software application or system to ensure that it meets specified requirements and performs as expected. It involves executing the software to find defects or errors and ensure its quality, reliability, and functionality.
Software testing typically involves the following key activities:
Data Science Training in Pune