🌟New Feature: Independent Grace Periods for SCA Findings

Greetings all! We wanted to let you know about a brand new feature in Veracode policies that provides you with the ability to manage grace periods for Veracode Software Composition Analysis (SCA) findings separately from other application findings. This gives organizations the ability to add SCA into policies with a longer grace period, which gives visibility into SCA work requirements without immediately causing the applications to fail policy. This feature was released yesterday and is now available to all Veracode customers.

 

Why did we make this change? Previously, one grace period was applied to Veracode SCA, SAST, and DAST findings. This made adding SCA to your policy a challenge, as any SCA security debt could cause the application to immediately fail your policy. With this change, you can now set Independent grace periods for Veracode SCA based on CVSS score ranges. This also implies that if a grace period is desired for SCA findings, policy rules for SCA should set on CVSS score rather than the severity. (The CVSS scores that map to Veracode Severity ranges that can be used in policy rules and grace periods can be found in the Help Center.)

 

When adding SCA rules to existing policies, Veracode recommends to initially set longer grace periods and to provide a pre-communicated “amnesty period” for development teams. If not, the common grace periods across all products may immediately cause multiple applications to fall out of policy compliance. By using the independent grace periods for SCA, the policy compliance state will become “conditional” during the grace period if the applications were previously passing. The SCA findings will be indicated as needed to be fixed per policy to bring applications into compliance. After the desired amnesty period, teams can adjust policy to the desired number of days to achieve compliance.

 

Users with the Policy Administrator role can set SCA grace periods by CVSS score, component block list, or license risk in the Policies menu. A screenshot showing the new fields is below.

 

Please note, Veracode SCA’s independent Grace Period data is not yet available in Analytics, as a result, your dashboards will not reflect the SCA Grace Periods. Veracode is working on providing support for this as soon as possible.

 

Further documentation for this feature can be found in the Help Center. You can also find guidance for using this feature in the updated SCA Deployment Guide and Policy Best Practices Guide.

 

Questions or feedback? Please leave a comment here! 

 

policy-edit-sca-grace-periods


Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.