lucas.ferreira likes this.
  • @SamHouston (Veracode)​ 

    • First of all, it's very important understand all tools that we have internally (repo, CI/CD, ticketing system, IDE's).
    • What development workflow works
    • Create or select security policies by groups apps
    • Know how many apps we have, the languages used and their business criticality can be very helpful too because knowing that it's possible to design a plan of integration:
      • starting by the most critical apps, doing the packaging correctly and attaching the right security policy
      • Depending of the scenario, we can do all apps from a specific language and by product (first SAST upload and scan, when its finished start SCA agent, etc...)
    • When all apps are scanned and integrated into our SLDC, we start to create and collect Dashboards reports to understand our maturity and design the nexts steps for remediation of vulnerabilities

     

    Expand Post
    Selected as Best
  • @SamHouston (Veracode)​ 

    • First of all, it's very important understand all tools that we have internally (repo, CI/CD, ticketing system, IDE's).
    • What development workflow works
    • Create or select security policies by groups apps
    • Know how many apps we have, the languages used and their business criticality can be very helpful too because knowing that it's possible to design a plan of integration:
      • starting by the most critical apps, doing the packaging correctly and attaching the right security policy
      • Depending of the scenario, we can do all apps from a specific language and by product (first SAST upload and scan, when its finished start SCA agent, etc...)
    • When all apps are scanned and integrated into our SLDC, we start to create and collect Dashboards reports to understand our maturity and design the nexts steps for remediation of vulnerabilities

     

    Expand Post
    Selected as Best

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.