Scott (Community Member) asked a question.

What is required to achieve Verified Continuous?

Veracode's site lists 9 requirements for Continuous. I'm looking into achieving this for an application, but I don't understand what the last three mean. Is there a better description of what each means and what is needed to achieve it?

 

https://community.veracode.com/s/get-verified#verified-tiers

  1. Security Tools integrated into SDLC
  2. Defined policy doesn't allow Very High, High and Medium flaws in 1st party code
  3. Open source policy doesn't allow very High, High and Medium vulnerabilities
  4. Biannual mitigation review
  5. 30-day remediation period
  6. Scanning cadence < every 60 days
  7. Post-production security assessment
  8. Advanced Security Champions Training
  9. Secure Coding developer training

 

1 - Vague, but i think i generally get the intent which is "have a program around scanning, don't have it be ad-hoc"

2 - Straightforward - Veracode Policy

3 - Straightforward - Veracode Policy

4 - Purchase and Use MPR twice a year

5 - Straightforward - Veracode Policy

6 - Scan more than once each 60 days.

7 - ? is this Manual Pen Test?

8 - ? is this eLearning based?

9. - ? is this Security Labs based?

 

I did a search on community and didn't return any results, so i'm posting this. Feel free to direct me to the appropriate place if it already is documented.


EGertis462759 likes this.
  • EGertis462759 (Community Member)

    You need a security champion and they need to pass the first two eLearning certification levels.

  • Hello @Scott (Community Member)​: here are the official criteria for achieving Verified Continuous:

     

    1. Conducted a SAST scan in the past 2 months
    2. No Medium (Sev3) or above flaws in SAST results
    3. No Mitigations in ‘Proposed’ State
    4. If Mitigations have been Approved: Biannual mitigation review
    5. Conducted SCA scan (either Upload & Scan or Agent-Based) in the past 2 months
    6. No Medium (Sev3) or above flaws in SCA results
    7. Conducted either MPT or Dynamic scan
    8. No Medium (Sev3) or above flaws in aforementioned scan
    9. Used APIs to Automate Scanning on Application Profile
    10. Ran an IDE Scan in the past 2 months
    11. Named Security Champion achieves either: A Learner Level 3 badge in eLearning, or 200 points in Security Labs
    12. At least 5 developers achieve either: A Learner Level 2 badge in eLearning, or 100 points in Security Labs

     

    Each of these items maps in some way to the list provided in your original post. Let me know if you have any other questions with this.

    Expand Post
    • Scott (Community Member)

      1. Thanks @Matthew, Customer Support (Veracode)​ , one clarification on #4 "If Mitigations have been Approved: Biannual mitigation review". I'm reading your answer as this is reviewing all Approved Mitigations twice a year to ensure they are still applicable. Is there a way where we are expected to reflect this in the platform - e.g. adding a fresh comment, or by rejecting past mitigation approvals and re-approving them all? Or is this an operational item we take outside of the platform and self-certify on?
      Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.