🌟Product Update: Policy Evaluation Timeframes and Policy Best Practices

Greetings all, @Tim J (Veracode PM) (Veracode)​ here with an exciting new feature in Policies. You can now specify an evaluation timeframe for your policy so that only findings in the evaluation timeframe affect the policy evaluation. This feature is useful for two use cases:

  • Enforce a policy on an application with existing security debt: By defining a policy evaluation timeframe that only looks at findings found after the first scan, you can break the build on new policy violating findings while giving the development team time to work down the backlog of security debt.
  • "Freeze" a set of findings prior to application release: By defining a policy evaluation timeframe that only considers findings before a certain date, you can exclude new findings introduced late in the development process, for instance by a new Veracode static engine version

 

By default your existing policies are unchanged, but you can add an evaluation timeframe to any existing policy.

 

We're very excited about providing this feature, as giving customers a means to enforce policy on applications with security debt has been a frequent request. Thanks to all who provided feedback!

 

You can learn more about this feature in the Help Center. Also, to accompany this feature, we have written a Policy Best Practices guide (attached) that provides guidelines for getting started with custom policies, including how to use this new feature. Check it out and let us know what you think!

 

Screenshot

policy-edit-eval-timeframePolicy Edit screen showing the Evaluation Timeframe section

 


Topics (6)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.