Skip to main content

General security policy rules

The following security policy rules apply to multiple scan types, except for Software Composition Analysis (SCA). For SCA, see SCA security policy rules. These rules define the security requirements that scanned applications must meet to pass policy. They are preconfigured in the built-in policies.

To add these rules to a custom policy in the Veracode Platform, create or edit a custom policy and select the rules from the Rule Type dropdown in the Add New Rule dialog.

You can also add and configure these rules with the Policy API.

Findings by Severity

This rule disallows findings that meet or exceed a specified severity rating for the selected scan types.

In the Veracode Platform, in the Add New Rule dialog, select one or more scan types to which to apply this rule. For Requirement, select a severity rating.

Supported scan types: Container scans, IaC scans, SCA Upload and Scan, Static Analysis, Dynamic Analysis, and Manual Penetration Testing

Findings in CWE Category

This rule specifies CWE categories that mustn't have any associated findings in the application.

In the Veracode Platform, in the Add New Rule dialog, for Requirement, select one or more CWEs that violate security standards.

Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing

Findings with CWE ID

This rule specifies one or more CWE IDs that mustn't be listed in the findings for the application.

In the Veracode Platform, in the Add New Rule dialog, for Requirement, search the CWEs table and select one or more CWE IDs.

Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing

Findings within Scan Type

This rule ensures the application doesn't contain any findings from the selected scan types.

In the Veracode Platform, in the Add New Rule dialog, for Requirement, select one or more scan types.

Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing

Minimum Scan Score

This rule requires the application to meet or exceed a specified Security Quality Score.

In the Veracode Platform, in the Add New Rule dialog, for Requirement, enter a score value between 1 and 100.

note

Dynamic Analysis scans must be linked to application profiles.

Supported scan types: Static Analysis and Dynamic Analysis

Security Standard

This rule requires that the application doesn't contain findings defined by selected standards, including PCI, OWASP, OWASP Mobile, CWE Top 25, or CERT. For the list of CWEs that we support for each standard, see CWEs that violate security standards.

In the Veracode Platform, in the Add New Rule dialog, for Requirement, select one or more supported security standards.

If you select the following requirements, when the Veracode Platform supports new versions of these standards, it automatically reassesses scanned applications against the new standards.

  • Auto-Update PCI
  • Auto-Update OWASP
  • OWASP Mobile
  • Auto-Update CWE Top 25
  • Auto-Update CERT

Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing