What It Means to Remediate vs Mitigate a Flaw?

So, now that you’ve successfully performed your first Veracode scan, the next step in the workflow is to review the findings in greater detail via the Triage Flaws view to help develop a remediation (or mitigation) strategy.

Remediation is a code change that eliminates the risk at the root, in a way that is programmatically verifiable by the Veracode Scanner. In other words, a flaw Veracode found in the previous scan within the policy or sandbox, but did not find again in the current scan. You can click the triangle next to a flaw ID to view details about the flaw, including remediation guidance, flaw descriptions, links to software security resources, and links to recommended Veracode eLearning courses and tutorials.

Alternatively, Veracode also enables you to sort the flaws and decide if you want to take any mitigation actions to temporarily address the flaw as opposed to remediating, such as by making changes to the operating system features, network implementation or application design. A mitigation may be appropriate if the result of:  

  • A compensating control outside the scope of analysis that reduces or eliminates the risk identified by the flaw being reported.  
  • A compensating control inside the logic of the application that the Veracode scanner is unable to confirm as effective or present in all circumstances.  
  • A deliberate implementation decision, which is inherently risky, but required to provide the needed functionality.
  • ​​​​​​​If the Veracode Scanner has potentially incorrectly identified something as a flaw or the flaw is not relevant in a security context (Potential False Positive), this would also be another circumstance where the mitigation workflow is followed.  

​​​​​​​The mark of an effective AppSec program isn’t just finding flaws, but demonstrating the ability to fix them. Veracode specializes in making sure you understand the significance of the findings and provides guidance on remediation and mitigation techniques. Scan results calls can be scheduled with our team of Application Security Experts from directly within the Veracode Platform by choosing the “Schedule a Consultation” option when viewing the report for a completed scan.

Topics (3)

Related Topics

    Ask the Community

    Get answers, share a use case, discuss your favorite features, or get input from the Community.