VeraTip: Which flaws do you fix first?

Hello community!  

 

My name is Ashish and I’m a Customer Success Manager at Veracode. I’ve been helping organizations implement Veracode for the last five years. One question I often get is, among so many vulnerabilities found by Veracode, where should I start? 

 

From my experience, it depends on whether there’s a particular policy you need to pass. If you’re just getting started, I recommend beginning with achievable policy standards. Once you’ve determined the policy you’ll use, there are two steps I recommend when prioritizing remediation: 

 

  • Severity and Ease of Fix –The “Fix First Analyzer” give you an idea of which flaws to fix first to improve the overall security posture of the application. 
  • Exploitability – Within a given group of flaws in the Fix First Analyzer, you can sort the flaws by exploitability to further prioritize them, beginning with flaws that are Very Likely to be exploited. 

 

Do you and your team follow a similar approach to prioritize flaws for remediation? What are other things that you take into consideration when developing your remediation strategy?

 

📖  In case you’re new to triaging flaws:

Check out this article where I shared a few things you can do to prioritize flaw remediation.


HemantShah and EGertis462759 like this.
  • EGertis462759 (Community Member)

    This is a great question and the provided answer is extremely helpful.

  • HemantShah (Community Member)

    "Fix First Analyzer" is a great source to start with. However before that I would recommend to have organization wide acceptable Risk Policy - That will help you to summarize what level/type of issues your organization want to consider on priority. Once you have list of flaws based on Risk Policy then you can apply filter by "Fix for Policy" and then pick the flaws based on their severity and Exploitability. From my perspective we should aim not to have any Very High/High open all the time, and then we should work to remediate the Medium ones. You can also configure grace period to make the development team to work on priority bases based on configured preferences.

    Expand Post
  • GBorer971714 (Community Member)

    Those mistakes range from functional, compilation, runtime, syntactical, and logical errors to missing commands, communication problems, and so IndigoCard on. They can make an app malfunction or crash and also make it vulnerable to attacks.

     

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.