Try our new research platform with insights from 80,000+ expert users

Veracode Policy Reporting - Compliance

What is your impression of the solution’s policy reporting for ensuring compliance with industry standards and regulations, if applicable. Please explain.

reviewer2067186 - PeerSpot reviewer
Product Marketer at a media company with 1,001-5,000 employees
The compliance reporting is a great feature because there are a lot of different frameworks and channels, and each unique channel has its individual compliance monitoring and policies. Veracode helps us prepare for all the different challenges.
View full review »
AK
LSA at a consultancy with 10,001+ employees
Veracode's policy reporting for ensuring compliance with industry standards is excellent. The report helps us maintain our compliance.
View full review »
SA
Manager IT at a tech company with 201-500 employees
Veracode provides compliance reporting so we can identify issues without having to rely on complaints.
View full review »
SC
Systems Engineer at Shiftmovers
It streamlines compliance, policy management, and reporting on various data analytics. We use it daily to gain insight into our work processes.
View full review »
reviewer2249226 - PeerSpot reviewer
Executive Assistant at a tech company with 51-200 employees
Veracode's policy reporting for insurance compliance with industry standards and regulations is good. We can integrate numerous reports, and the positive reporting feature is also highly commendable.
View full review »
Robert Hood - PeerSpot reviewer
Information Security Architect at a tech vendor with 5,001-10,000 employees
Veracode's policy reporting for ensuring compliance with industry standards and regulations is excellent. It is applicable to us as a multinational company with PCI and HIPAA requirements, and we also engage in government projects. Consequently, we are obliged to adhere to any relevant regulations, which is why we have implemented numerous policies that automatically alert us when any action might potentially violate the established guidelines.
View full review »
OK
Sr. Development Manager at RWS Holdings PLC
We are using our internal policies for the WAF Security Standard, but it isn't an industry-wide policy. We are not using PCI DSS, etc., but it shouldn't be a problem to comply with that stuff. For example, PCI DSS isn't applicable to our case because we aren't managing any credit card data, working with medical devices, or doing anything involving the military. Some standards aren't applicable.
View full review »
Oscar Narvaez - PeerSpot reviewer
COE Head at a tech services company with 1,001-5,000 employees
I work in Latin America, and there are regulations on information security and the use of customer information. The most vital areas are things like health information and finance. You can face penalties for failing to protect customer information, so it's critical for us to secure our code during development. Any vulnerable code or application component can risk disclosing customer information from customers and allowing an outsider to penetrate the systems or databases.
View full review »
reviewer1699062 - PeerSpot reviewer
Sales Engineer at a computer software company with 51-200 employees
Veracode is very good for ensuring compliance with industry standards and regulations. We can have many dashboards and reports related to policy management.
It is very good for ensuring compliance with industry standards and regulations. We can have many dashboards and reports related to policy management.
View full review »
Arnab Paul - PeerSpot reviewer
Cyber Security Consultant at a consultancy with 10,001+ employees
Using Veracode policy regulations, we can offer predefined rules. When setting up any application, we establish the application name and other necessary details. Following this, there is a section where we can input this information. Essentially, there exist predefined regulations which we can either directly utilize if they suit our needs, or adjust them based on the requirements of our project team. Therefore, we have a pre-existing set of rules and functionalities available.
View full review »
Sairam Bathini - PeerSpot reviewer
DevSecOps Engineer at Tata Consultancy
We are satisfied with the solution’s policy reporting for ensuring compliance with industry standards and regulations.
View full review »
PB
ML engineer at a consultancy with 10,001+ employees
In my organization, we have a policy in place. Every company has a different policy; at least our company has specific requirements where we expect everyone to build the tool or the software to some extent, following some best practices. Veracode helps us embed those policies into the scan. When we run the scan, the administrators have already set the policy, defining what needs to be checked and what can be ignored. It helps us when we run the scan because it provides a score based on the policy level. This score certifies how well the tool has scanned the code.
View full review »
Pradeep Kumar. - PeerSpot reviewer
Founder and Director at Bizcarta Technologies India Pvt Ltd
The solution’s policy reporting for ensuring compliance with industry standards and regulations is good.
View full review »
Freddy Bang. - PeerSpot reviewer
Chief Technology Officer at ELEARNINGFORCE International ApS
Its policy reporting for compliance is also very good. It meets our meets our needs.
View full review »
reviewer2287986 - PeerSpot reviewer
Lead Product Security Engineer at a computer software company with 1,001-5,000 employees
The policy reporting is incredibly robust.
View full review »
GR
System Engineer at a tech vendor with 10,001+ employees
Veracode's policy reporting ensures compliance with industry standards and regulations. It also provides a detailed report with multiple options. We can easily generate a report of four to ten pages, or even a one-page report. I really like the way Veracode generates reports on assessments. It's my favorite feature.
View full review »
reviewer2296401 - PeerSpot reviewer
CyberSec professional at a manufacturing company with 5,001-10,000 employees
I am using Veracode's preconfigured policies because I find them useful and complex.
View full review »
Jan Pašek - PeerSpot reviewer
Tech Lead at a financial services firm with 10,001+ employees
Overall, I think it's great that the firm can configure certain policies to monitor applications, and the flaw report also enables us to see the flaws that need to be fixed to become compliant, which is a good feature. From Veracode's perspective, everything looks fine.
View full review »
Vikas Agrawal - PeerSpot reviewer
DevOps Lead at HealthEdge Software, Inc.
Another aspect that is quite good is the policy reporting for ensuring compliance with industry standards and regulations. Initially, we were using freeware tools, but we are quite impressed with how Veracode gives the most detailed and latest vulnerability and security information.
View full review »
TR
Associate Software Engineer at a healthcare company with 201-500 employees
Veracode's policy reporting for ensuring compliance with industry standards and regulations is good. Veracode covers a vast majority of industry standards and identifies areas within our code that don't comply with those standards, providing remediation suggestions.
View full review »
reviewer2333736 - PeerSpot reviewer
Cloud system engineer at a consultancy with 1-10 employees
Veracode's policy reporting for ensuring compliance with industry standards and regulations has been positive for our organization.
View full review »
Ujjwal Sachdeva - PeerSpot reviewer
Data scientist at Advarisk
The solution's policy reporting for insurance compliance with industry standards and regulations is very helpful. It's fast as well. The team helps us at every step of the product life cycle.
View full review »
Deepak Naik - PeerSpot reviewer
Chief Security Officer at Digite
Veracode aligns with SOC, ISO, and other types of certifications. It helps with compliance that Veracode has all these reporting formats.
View full review »
Evan Gertis - PeerSpot reviewer
Penetration Tester at a tech vendor with 51-200 employees
None of these executives believe anything these users are saying until they can see the results. They want that dashboard report. In less than three weeks, a junior security engineer can learn to create a dashboard easily that will allow the organization to stay on top of the most important things. They need to show the stakeholders that we're doing something here. They'll get the certification and see the dashboards. You now have something that's actually worth $2,000. With these other ones, who knows what you'll get.
View full review »
reviewer2381340 - PeerSpot reviewer
Lead Consultant DevOps and Infrastructure at a tech vendor with 5,001-10,000 employees
Veracode's policy reporting is valuable because it provides two key benefits: first, it generates a security score for our application. Second, it offers comprehensive reporting that details both the vulnerabilities found and the potential risks they pose to our application.
View full review »
David-Robertson - PeerSpot reviewer
Director Enterprise Architecture at Exeter Finance Corp.
Veracode is very good at ensuring compliance with industry standards.
View full review »
HS
Works
The policy reporting does assist us with compliance. There are certain rules where fixing vulnerabilities is part of the policy. We have guidelines and we need to resolve them before putting something into a higher environment. It helps with that.
View full review »
DK
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Veracode's policy reporting for ensuring compliance with industry standards and regulations is satisfactory.
View full review »