FGuerra553066 (Community Member) asked a question.

Can I link a DAST url to an application without having the DAST flaws be evaluated by the policy?

We have our applications failing policy on High and above for Dynamic, Manual, and Static. We have been unable to remove the Dynamic from the policy, so we do not link any of our DAST urls to our applications, since all our applications would fail policy. Is there a way to link DAST urls without being evaluated by policy?

 

Findings by Severity

High and above not allowed

Dynamic, Manual, Static

Impacts Application Compliance: Yes

Impacts Agent Workspaces: No


  • SamHouston (Veracode)

    Hi @FGuerra553066 (Community Member)​ - the only option would be to remove dynamic from your policy so the DAST results don't impact the policy compliance. To your main question - no, it's not possible to link without having the results be evaluated by policy.

     

    It's best practice to remediate the vulnerabilities we're detecting, as that would help you stay compliant and within policy.

     

    Have a great day!

    Expand Post
  • FGuerra553066 (Community Member)

    Thank you for the info @SamHouston (Veracode)​ ! One of my supervisors attempted to remove dynamic from the policy, but it did not seem possible, like static and dynamic were paired together. Originally we did only have static in our policy, but recently we had to go through and unlink all of our applications. Was this a change that was made or is there another way to remove dynamic from our policy?

    • SamHouston (Veracode)

      Hi @FGuerra553066 (Community Member)​ Good catch, you're right - it looks like we have filed a feature request in our system to add more flexibility by scan type.

  • FGuerra553066 (Community Member)

    @SamHouston (Veracode)​ , are there any updates for this feature request? Or is there any way for us to explore DAST findings without having to link to an application?

    • SamHouston (Veracode)

      Hi @FGuerra553066 (Community Member)​ - It looks like this issue will be addressed with feature update/change that we're currently working through the product management/planning process. I've left a note internally to nudge w/your request 🙂

Topics (5)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.