
Anne N (Veracode PM) (Veracode) asked a question.
Hi All,
Veracode product management here and I wanted to share a bit about the new mitigation types "Accept the Risk" as well as "Reported to Library Maintainer".
We regularly review the data on mitigation proposals to determine if there are trends in findings marked as false positives or in the way our customers are using our product.
Two trends have become apparent in recent years in the mitigation comments we see: developers have been making statements that the risk was owned by a 2nd party / external development team or that the business ultimately accepts that the risk from the finding exists but would not be acted upon. We addressed this 2nd party theme through the recently released mitigation type "Reported to Library Maintainer" and now we are addressing the latter trend through the "Accept the Risk" mitigation type.
By creating two new mitigation types we are providing for better management, oversight, and tracking of behavior that already exists in the our workflows today. These mitigation types require the review and approval workflow so will still necessitate a level of review and feedback to the development team.
Ultimately the new Accept the Risk mitigation type should denote that the business accepts the risk associated with this finding after careful evaluation of all other options and a determination that the cost of implementing other controls or fixing this finding is not worth the value of the reduction in risk.
I hope these two new types work well for your AppSec program! Happy scanning!
Anne
.png)
This great but Busniess don't usually accept a risk forever. There should be an option to set a timeline and accepting a risk.
We are exploring our options for providing some sort of expiration functionality but it is not on roadmap at this time. You can use the community project "VcodeMitigationExpire" available here https://github.com/veracode/Veracode-Community-Projects to expire mitigations after a period of time