VeraTip: What program, process, or workflow did you add to your organization alongside the Veracode tools?

Hi community (to our veteran users)!

 

Many members in the Base Camp group are just getting started with the implementation of the Veracode tools and standing up the AppSec program for their organizations. One thing that’s very important in the “build" stage is having the right people, process, and workflow – alongside the right technology – in place.

 

Recounting the early days of building your AppSec programs, which workflows, processes, or people did you bring together with technology to build the foundation of your program?

 

📖 Some inspirations |

@DeCaPa (Community Member)​, a security architect at a global company in the travel industry and one of the Star Members in our community, recently wrote an article and boiled down into five steps how he built the “softer side” of starting an AppSec program.

The basics

Step 1: Understand your landscape: how to plan your resources?

Step 2: Leverage your Veracode resources: what’s a consultation call?

Step 3: User access to the Veracode Platform: Who should see what?

 

The path towards maturity

Step 4: Create a roadmap: What to consider when creating a roadmap?

Step 5: Show your Value: What to include in your reports?

 

Have questions for @DeCaPa (Community Member)​ about the article? Post them below!


  • EGertis462759 (Community Member)

    This is an excellent question.

     

    Step 1: Understand Your Landscape

    We are a medium size company and relatively lean Devops team.

     

    Step 2: Leverage Your Veracode Resources

    We need to save time and money. Automation is a critical part of workflow. Our scanning is automated via Jenkins. We leverage the JIRA plugin to create tickets for flaws. Developers use the veracode IDE integration to address their assigned flaws.

     

    Step 3: User Access to the Veracode Platform

    As a part of the onboarding process for new hires an administrator creates a new account for each developer. They have access to e-learning courses and scan results.

     

    Step 4: Maturity

    We work through simple proof of concepts. We plan a simple test, execute it, and then learn from it. Each quarter we strive to reach a new veracode level.

     

    Step 5: Show Your Value

    We use the pre-built veracode dashboards to gauge our performance. As we grow we'll learn which metrics are the most important based on feedback from upper management.

     

    @DeCaPa (Community Member)​ wrote an excellent article. We are thankful to have this community and people like Meghan Stewart and Eric Knoll helping us on our journey. I would love to get feedback from more senior professionals on our workflow.

    Expand Post
  • HemantShah (Community Member)

    Step 1: Understand your landscape

    We are mid to large size company. primarily into field of software development.

     

    Step 2: Leverage your Veracode resources

    with the help of customer success manager (CSM) we try to make best use of the veracode resources by creating the measurable success plan, that includes automation.

     

    Step 3: User access to the Veracode Platform

    for all the initiatives we do onboarding session with help of CSM, after that with help of SSO integration with Veracode we onboard applications and users to perform defined set of activities.

     

    Step 4: Create a roadmap

    for bringing maturity in the program with the help CSM we used to make a roadmap to success, keep on reviewing the reports, policies etc.. We set some goals for application the application development team to reach to the next level from the earlier.

     

    Step 5: Show your Value

    We definitely make use of veracode analytics dashboard but apart from that with use of REST API we also develop our on reports that gives more meaningful presentations to the exec teams.

     

    This is great to see how other teams across globe are putting efforts. Definitely a way to learn. @DeCaPa (Community Member)​ , @EGertis462759 (Community Member)​ , thanks for sharing this,

     

    Expand Post
  • JBridges607116 (Community Member)

    Protecting your web applications in high-speed QA and production cycles is paramount, but developers don’t have time to manage multiple on-premises scanning tools or interpret complex reports.

     

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.