lucas.ferreira likes this.
  • hello @SamHouston (Veracode)​ 

     

    First off all, we need to have a very strong security policy established in company. This will reflect our actions and management of policies into Veracode.

     

    Then, we'll need to have a very clear understanding the criticality of our applications for business, example: what are critical, high, medium and low. This will affect our management. We can create a security policy for critical and high, one for medium and one for low. The result expected is prioritize what applications is more important and what weaknesses and vulnerabilities will impact the business risk negatively.

     

    After submit applications to scans, we'll need to understand what CVEs and CWEs affect the compliance, likelyhood of exploitation and the business impact in case of exploitation or security incident when these weaknesess are attacked.

     

    We can use tools in Veracode platform like: Fix First Analyzer that will help a lot saving time and effort, but, I really believe that we can use other filters together like Fix for policy = required.

    Further to that, we can use Flaw Sources, to see if a particular CWE affect other parts of my code, for SCA, looking for vulnerable methods, DAST what the most dangerous weaknesses are open to the wild.

     

    In my opinion, it's very important understand deep how CWEs and CVEs works into business context, because we can focus on that what really matters and will impact the company. After fixing those, we can follow the process previously implemented to fix the rest of findings.

     

    Expand Post
    Selected as Best
  • hello @SamHouston (Veracode)​ 

     

    First off all, we need to have a very strong security policy established in company. This will reflect our actions and management of policies into Veracode.

     

    Then, we'll need to have a very clear understanding the criticality of our applications for business, example: what are critical, high, medium and low. This will affect our management. We can create a security policy for critical and high, one for medium and one for low. The result expected is prioritize what applications is more important and what weaknesses and vulnerabilities will impact the business risk negatively.

     

    After submit applications to scans, we'll need to understand what CVEs and CWEs affect the compliance, likelyhood of exploitation and the business impact in case of exploitation or security incident when these weaknesess are attacked.

     

    We can use tools in Veracode platform like: Fix First Analyzer that will help a lot saving time and effort, but, I really believe that we can use other filters together like Fix for policy = required.

    Further to that, we can use Flaw Sources, to see if a particular CWE affect other parts of my code, for SCA, looking for vulnerable methods, DAST what the most dangerous weaknesses are open to the wild.

     

    In my opinion, it's very important understand deep how CWEs and CVEs works into business context, because we can focus on that what really matters and will impact the company. After fixing those, we can follow the process previously implemented to fix the rest of findings.

     

    Expand Post
    Selected as Best

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.