
MThangasamy708957 (Community Member) asked a question.
We are looking at Veracode reporting to support auditor inquiries and had a couple of questions.
One, is it possible to configure Veracode to look at a specific portal (we currently scan all that we have), and two, is it possible to provide some 'proof' of the validation rules we're using?
I'm not sure if Veracode provides updates for the latest vulnerabilities, or if we set up the validation rules on our own (or some combination of the two). Our Director would like to know what input validation rules are being referenced (and if we can provide proof of that, a code snippet, input rules report, something like that)
Any help is appreciated!
.png)
Veracode can provide letters of attestation that gives a reports on the scan analysis for an application. In addition, the policy which you create to apply to application scans can be customized to reflect the validation rules that makes sense for your business. The Veracode Platform also has default policies that reflect the more common requirements based on the criticality of an application to our business, including OWASP TOP 10, SANS 25 and PCI standards.
Finally, the Veracode Verified program can provide an ongoing validation of the security you have built into your software development process. You can find out more about the Verified program at www.veracode.com/verified. If your application(s) qualify for one of the Verified tiers, you can submit the request to receive a Verified seal here in the Community under the "Get Verified" menu option.