New Case Study: How SEF/MG Reached 99.6% Application Scan Coverage

The Secretaria de Estado de Fazenda de Minas Gerais (SEF/MG), Brazil's Minas Gerais state revenue department, has published its application security journey with Veracode — and there's a lot here for anyone scaling AppSec across a large development organization.

 

With 300 developers and a significant legacy footprint, SEF/MG needed to move from catching vulnerabilities right before production to finding them during development. They integrated Veracode Static Analysis and Software Composition Analysis directly into their GitLab and Azure DevOps pipelines via API, and paired it with Veracode eLearning to build security skills across the team.

 

Highlights from the case study:

  • 99.6% scan coverage (283 of 284 repositories)
  • Policy compliance up from 10.5% to 49.6%, peaking at 73.5%
  • Mean time to remediate of roughly 40 days
  • 100% developer adoption of automated scanning
  • Strengthened support for ISO 27001, LGPD, and CIS

 

Read the full case study here:

https://www.veracode.com/case-studies/sef-mg-devsecops-veracode/


Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.