What are the initial questions you answered using Veracode Analytics?

Hi Community!  

 

My name is Emma and I'm a Security Program Manager here at Veracode. My goal as a Program Manager is to guide my client’s AppSec programs from onboarding to full automation and sustainable best practices. Throughout your program, Veracode Analytics can provide answers to questions your developers, managers, and C-suite ask regarding the value security testing provides and risk reduction to your organization.  

 

Having coached many organizations on beginning with Veracode Analytics, I found the easiest (yet most critical) first step is asking the right questions – the questions that address the goals of a program. Before digging too deep and getting lost in the data, I always recommend my clients to step back and consider what questions they want to answer first? 

 

In Beginner’s Guide to Veracode Analytics: Start with the Right Questions, I shared four most common questions my clients start with as well as how to use pre-built dashboards to answer them: 

  • "How are my apps holding up against internal compliance?"  – Policy Compliance Trend dashboard 
  • "What flaws were found and how good are we at fixing them?" – Findings and Remediation Details dashboard 
  • "How often are we scanning and through what channels?" – Scanning Trends dashboard 
  • "Who is shipping the safest/riskiest code? "– Performance Reports dashboard 

 

💡 I know many of you have extensive experience with Veracode Analytics. I'm curious: 

  • What are the first few questions you started answering using Veracode Analytics and why? 
  • How did you answer those questions? What metrics/dashboards did you use? 

  • esweeney (Veracode.com)

    I am curious to see what are the top priorities your management sets forth for security testing. Does your business focus on compliance and standardization based on a highly-regulatory industry? Or is your goal to automate and integrate testing to evangelize security for the first time within your development organization? Veracode Analytics can help share your program's story with higher and lower management to get these priorities across!

    Expand Post
  • ABacchi035478 (Community Member)

    We were trying to answer what is being found with scans in Veracode and how much is being fixed per month. We were able to display the newly found flaws per month from Med-V High as bars, then next to it show the count of flaws fixed that month. Along with that we are showing the number of static scans performed that month as a line chart overlay to show if there is a reason we may have found more or less flaws in one month (More scans might mean more flaws found). We have had some decent success with this type of combination chart so far.

    We are also having some fun with adding custom fields for senior leadership per team and applying the names or sr leadership to each app in an automated way- now we can create leaderboards showing which senior leaders have the most flaws in their orgs etc.

    Expand Post
  • DeCaPa (Community Member)

    I'll have to tip my hat to the policy compliance trend. These are intended for C-Suite to answer the simple question of "how secure are we?". If set up properly, the Analytics platform takes into account the way groups/roles are set up within the platform. Meaning it is possible to use the same dashboard up and down the organization, based on the users permissions to applications. Leverage team hierarchy and business units to reflect your org structure. I found that it reduces the number of dashboards that need to be created.

     

    I also agree with @ABacchi035478 (Community Member)​ regarding leader boards. A little friendly competition usually serves as a good motivator to improve.

    Expand Post
  • mwaldis335267 (Community Member)

    The key question is how are you doing, is your security posture improving? We use are own customized dashboards because of the uniqueness of our processes. I only show the data occasionally to management its not required but it gives us a good status of where we have been 6 months ago and what we have in place now. I have 4 dashboards but the key things I look at are reopened flaws, fixed flaws, very high and high flaws, it gives you a quick indicator on how things are going over time. Nice feature of the product.

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.