Can anyone recommend how to use policy to manage AppSec programs?

How have you been using your AppSec policy to assess the results of your program? A strong policy is key to meeting your application security goals. What would you recommend other members consider when setting up the policy for their programs?

 

Need some inspiration on what to share? Here are some ideas:

  • Are you using a custom or pre-built policy?
  • Why are you using the policy you selected? 
  • How has policy influenced your organization's coding practices?

 

⚡️ Resource: New to policy? Check out this new article where @slusby (Veracode, Inc.)​ and @dhegelein (Veracode, Inc.)​, the AppSec program experts at Veracode, introduce policy basics.


  • Mark_M (Community Member)

    Without a clear, documented, and well-understood policy and standards related to AppSec, it's unlikely you'll achieve anything more than hit or miss compliance, and no chance you'll have an effective AppSec practice.

     

    A generic policy on the need for AppSec as a management commitment, along with a detailed standard on SPECIFIC security controls for the SDLC provides the best chance for getting development teams, second line controls checkers, and internal auditors all on the same page. The best standards tend to be simple, brief, and laden with links to implementation details so it's an effective communication tool.

     

    With a good standard, you can set up project-level Definition of Done User Stories to make sure the required controls are implemented correctly and work as intended. You can create as many DoD user stories as you have required activities in the standard, e.g. One for Security Champions to require a clean static scan, another for threat modeling, another for dynamic scanning, SCA, external Pen Testing, etc. This way, the teams take personal responsibility and commitment to making AppSec part and parcel of all work they do on application development, maintenance, and operations.

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.