
Scott (Community Member) asked a question.
Veracode's site lists 9 requirements for Continuous. I'm looking into achieving this for an application, but I don't understand what the last three mean. Is there a better description of what each means and what is needed to achieve it?
https://community.veracode.com/s/get-verified#verified-tiers
- Security Tools integrated into SDLC
- Defined policy doesn't allow Very High, High and Medium flaws in 1st party code
- Open source policy doesn't allow very High, High and Medium vulnerabilities
- Biannual mitigation review
- 30-day remediation period
- Scanning cadence < every 60 days
- Post-production security assessment
- Advanced Security Champions Training
- Secure Coding developer training
1 - Vague, but i think i generally get the intent which is "have a program around scanning, don't have it be ad-hoc"
2 - Straightforward - Veracode Policy
3 - Straightforward - Veracode Policy
4 - Purchase and Use MPR twice a year
5 - Straightforward - Veracode Policy
6 - Scan more than once each 60 days.
7 - ? is this Manual Pen Test?
8 - ? is this eLearning based?
9. - ? is this Security Labs based?
I did a search on community and didn't return any results, so i'm posting this. Feel free to direct me to the appropriate place if it already is documented.
.png)
You need a security champion and they need to pass the first two eLearning certification levels.
Hello @Scott (Community Member): here are the official criteria for achieving Verified Continuous:
Each of these items maps in some way to the list provided in your original post. Let me know if you have any other questions with this.