🎯New Analytics Features: Security Program Dashboard and Static Flaw Details

Hi all, wanted to provide a little more information about two new Analytics features that we announced today.

 

The Security Program Overview dashboard was designed based on input from customers and Veracode security program managers to highlight important statistics in your application security program. And — based on a frequent request — it also incorporates targets!

 

When viewing the dashboard, you can set targets for key metrics like policy compliance, API usage, flaws fixed, and scan coverage. You'll also get richer statistics on time to fix, months in compliance and days since last scan. Check out a preview of the dashboard below!

 

analytics-securityprogram 

Second, for folks that are building their own dashboards and reports, we'd like to note the ability of static flaw details in the Findings explore. This set of data dimensions includes details of the finding location, like the source file, line number, function in which the finding occurred, the actual function call where the flaw was found (aka the "sink"), and more. You can use these dimensions to produce tabular reports, identify applications that share findings in a common source file, and more.

 

Please leave a comment if you have questions about these features!

 

@Analytics Group​ 


KP7766, lucas.ferreira, and 2 others like this.
  • KP7766 (Community Member)

    Hi @Tim J (Veracode PM) (Veracode)​ and @Anne N (Veracode PM) (Veracode)​ - great new dashboard! My team is particularly excited about the "What is my policy compliance over time" view; it tells a compelling story.

     

    Our leadership wanted to see this aligned to Veracode's normal policy color scheme so it would be easy to read at a glance (Did Not Pass = red, Conditional Pass = orange, Pass = green), so I saved the tile on our own dashboard to manipulate the colors but discovered that there's no way to assign a static color to each one (as there usually would be under visualization setting -> "Series"). Instead, it looks like we can "order" chosen colors so whichever state appears first in the series is assigned the first color, next state gets the second color, etc... This means that over time as the data changes, the colors shift.

     

    For example, last week an app's first timeline state was Conditional Pass which I set to orange, but this week the oldest data point has shifted to Pass, so now all Passes are orange.

     

    Do you know of a way we could statically assign colors to each Policy Compliance state with this view? It will be featured widely in our reporting going forward, but I'd like to get the colors consistent before we roll it out. Thanks!

    Expand Post
  • Unfortunately, assigning specific colors to the Pass, Fail, Conditional Pass, Not Assessed values is not possible with the timeline visualization. The colors as assigned based on the order of the data, as you discovered. There is no way around this unfortunately and that is why we had to go with the Veracode color palette rather than the usual colors (green, red, yellow, grey) for these values. We have provided this feedback to the provider of the functionality that we white label to provide the analytics capability and we are hoping that this will be a future improvement.

    Expand Post
    • KP7766 (Community Member)

      Got it. Appreciate the clarification!

Topics (7)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.