Policy and Reporting

Define AppSec Policies and Measure Compliance

Set Clear Security Goals for Development

Set clear goals from the start, such as risk reduction and compliance with internal policies, contractual requirements, laws, and regulations. Empower confident decision-making. With defined policies, developers know exactly which issues to fix and what to ignore. Scale security requirements over time as your program matures.

Define Service-Level Agreements

Define policy rules around how often development teams need to scan and how quickly they need to fix certain security defects. Eliminate confusion and unnecessary work, and unify security and development processes.

Make Compliance Audits Easy

Get one clear report that looks across major analysis types with a clear pass/fail result based on previously defined criteria, which can be reported into the company’s GRC system. Understand the root cause so you can take decisive action. Assess against new security policies without rescanning the application.

Use Standard Policies or Customize

Use Veracode’s standard policies for major compliance regulations, such as OWASP, SANS Top 25, and PCI. As your AppSec program matures, fully customize policies to meet your specific requirements. Apply several policies to the same application profile, if required.

Request Demo