Sohlae (Community Member) asked a question.

Couple of Questions on How to Mitigate Flaws

I have a few questions regarding mitigating flaws found by a static scan.

  1. Where can I find the documentation on how to request mitigation?
  2. Who is the mitigation approver?
  3. If the flaw has been mitigated, will it be displayed in succeeding static scans?

lucas.ferreira likes this.
  • hello @Sohlae (Community Member)​ 

     

    1. https://docs.veracode.com/r/improve_mitigation << here is the first topic about mitigating flaws and you can see below of it the others
    2. Mitigation Approver is the responsible for look at the mitigations proposed by developers on each flaw within of Triage Flaws and accept or deny. Here there are some links that you can see for more information:
      1. https://docs.veracode.com/r/c_role_permissions
      2. https://docs.veracode.com/r/Accept_or_Reject_Mitigations_from_the_Triage_Flaws_Page
    3. Mitigation means that you did a workaround to "block" that flaw would be exposed and exploited, but, into your source code, continues with it
    Expand Post
    Selected as Best
  • Hi @Sohlae (Community Member)​ !

     

    To add on to the excellent documentation from @lucas.ferreira (M3Corp)​ :

    1. Lucas has already provided the documentation for the mitigation feature we provide, but note that process documentation is specific to each organization. You need to check in your own organization what the process is around mitigation approval.
    2. Again, this depends on the process your organization has around mitigation approval. Please contact your Veracode administrator.
    3. The flaw will be shown, but will be marked 'Mitigation Approved'. It will no longer block policy compliance and will no longer influence the score, it will be shown only for audit purposes.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.