General security policy rules
The following security policy rules apply to multiple scan types, except for Software Composition Analysis (SCA). For SCA, see SCA security policy rules. These rules define the security requirements that scanned applications must meet to pass policy. They are preconfigured in the built-in policies.
To add these rules to a custom policy in the Veracode Platform, create or edit a custom policy and select the rules from the Rule Type dropdown in the Add New Rule dialog.
You can also add and configure these rules with the Policy API.
Findings by Severity
This rule disallows findings that meet or exceed a specified severity rating for the selected scan types.
In the Veracode Platform, in the Add New Rule dialog, select one or more scan types to which to apply this rule. For Requirement, select a severity rating.
Supported scan types: Container scans, IaC scans, SCA Upload and Scan, Static Analysis, Dynamic Analysis, and Manual Penetration Testing
Findings in CWE Category
This rule specifies CWE categories that mustn't have any associated findings in the application.
In the Veracode Platform, in the Add New Rule dialog, for Requirement, select one or more CWEs that violate security standards.
Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing
Findings with CWE ID
This rule specifies one or more CWE IDs that mustn't be listed in the findings for the application.
In the Veracode Platform, in the Add New Rule dialog, for Requirement, search the CWEs table and select one or more CWE IDs.
Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing
Findings within Scan Type
This rule ensures the application doesn't contain any findings from the selected scan types.
In the Veracode Platform, in the Add New Rule dialog, for Requirement, select one or more scan types.
Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing
Minimum Scan Score
This rule requires the application to meet or exceed a specified Security Quality Score.
In the Veracode Platform, in the Add New Rule dialog, for Requirement, enter a score value between 1 and 100.
Dynamic Analysis scans must be linked to application profiles.
Supported scan types: Static Analysis and Dynamic Analysis
Security Standard
This rule requires that the application doesn't contain findings defined by selected standards, including PCI, OWASP, OWASP Mobile, CWE Top 25, or CERT. For the list of CWEs that we support for each standard, see CWEs that violate security standards.
In the Veracode Platform, in the Add New Rule dialog, for Requirement, select one or more supported security standards.
If you select the following requirements, when the Veracode Platform supports new versions of these standards, it automatically reassesses scanned applications against the new standards.
- Auto-Update PCI
- Auto-Update OWASP
- OWASP Mobile
- Auto-Update CWE Top 25
- Auto-Update CERT
Supported scan types: Static Analysis, Dynamic Analysis, and Manual Penetration Testing