JPyle954717 (Community Member) asked a question.

What is the difference between a policy scan and a sandbox scan? What are the best scenarios for each?

I'm trying to understand the differences between a policy scan and a sandbox scan. How do they differ? How are they alike? When should I use a policy scan and when should I use a sandbox scan?


  • HI @JPyle954717 (Community Member)​ ,

     

    I have provided some great information below on a Sandbox and a Policy Scanner that will help you with the differences and when to use them.

     

    When to use a Sandbox:

    The Sandbox feature of the Policy scanner should be used to facilitate the “Shift Left” concept in securing software. Shifting left simply means that, rather than waiting until an application is ready for product release to execute on the Security Assurance or Compliance use cases, Veracode enables the development team to scan early and often in alignment with their development practices. Sandboxes are intentionally excluded from the official policy evaluation. This gives the development team time to remediate issues before the release candidate or production application is assessed against the policy for a formal pass/fail determination.

    Sandboxes should be considered “ephemeral” as their results will be deleted every 90 days.

    The primary use cases we are solving for include:

    1. Ad hoc Developer Testing: Sandboxes can be created for individual developers for ad hoc testing of whole modules or whole programs. Flaws that could affect policy if allowed to persist are flagged for remediation.
    2. Automated Testing: Sandboxes can be created to align with development stages or feature branches. Regular scanning occurs via automated interaction between a build system, CI system, or other orchestration system utilizing Veracode’s plugins, APIs, and CI tools.

     

    When to use a Policy Scanner:

    The Veracode Policy scanner is intended to provide the business with an understanding of the security posture of an application, so it should be run on a periodic basis and at minimum be the final step before releasing software. The Policy evaluation engine provides extensive options to enforce security best practices. Policy scans should be conducted against release candidates or production applications.

    The primary use cases include:

    1. Security Assurance: Security teams are provided with the ability to centrally establish application security policies that are appropriate for their business. These policies include requirements for the development team to ensure a mutual understanding of the risk tolerance of the business. Policy requirements can include scan type/frequency, industry best practices/standards/compliance, the inclusion of vulnerable third-party dependencies, and the age of flaws found. Once an application has been scanned, the policy evaluation engine makes a pass/fail determination based on the policy assigned to the application.
    2. Compliance: Many enterprises are subject to various regulatory bodies that require compliance with industry standards. The Veracode Policy scanner allows the security and development organizations to demonstrate clear adherence to these standards with robust audit logs, and the ability to provide attestation reports.

     

    Kind regards,

    Steven

    Veracode Support Engineer

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.