Product Update: "Accept the Risk" mitigation type now available

Hi All,

Veracode product management here and I wanted to share a bit about the new mitigation types "Accept the Risk" as well as "Reported to Library Maintainer".

 

We regularly review the data on mitigation proposals to determine if there are trends in findings marked as false positives or in the way our customers are using our product.

 

Two trends have become apparent in recent years in the mitigation comments we see: developers have been making statements that the risk was owned by a 2nd party / external development team or that the business ultimately accepts that the risk from the finding exists but would not be acted upon. We addressed this 2nd party theme through the recently released mitigation type "Reported to Library Maintainer" and now we are addressing the latter trend through the "Accept the Risk" mitigation type.

 

By creating two new mitigation types we are providing for better management, oversight, and tracking of behavior that already exists in the our workflows today. These mitigation types require the review and approval workflow so will still necessitate a level of review and feedback to the development team. 

 

Ultimately the new Accept the Risk mitigation type should denote that the business accepts the risk associated with this finding after careful evaluation of all other options and a determination that the cost of implementing other controls or fixing this finding is not worth the value of the reduction in risk.

 

I hope these two new types work well for your AppSec program! Happy scanning!

Anne


Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.