Whitepapers



Guide to Software Risk Assessments

This whitepaper outlines how new application security technologies enable organizations to meet the growing threat posed by software and provides risk management best practices which enterprises can use to secure their application inventory.

 
PCI Guide for Merchants and Service Providers

This whitepaper helps Merchants and Service Providers understand and meet PCI DSS requirements.

 
Five Steps to Secure Outsourced Application Development

Download the guide – "Five Steps to Secure Outsourced Application Development” and learn how independent verification and validation of offshore software, delivered through an on-demand service, can automate security acceptance testing and secure your enterprise.

 
Automating Code Reviews

On-demand application security testing offered as an outsourced service – based on binary analysis and multiple scanning technologies – is a major step toward reducing risk in applications developed in house as well as applications purchased from third party vendors. Learn how moving to a SaaS model for application security can automate your code reviews.

 
PCI Guide for Payment Vendors

This whitepaper explains how Payment Vendors can meet Visa PABP requirements and prepare for PCI PA-DSS compliance.

 
Understanding NIST 800-37 FISMA Requirements

As part of its FISMA responsibility to develop standards and guidance for federal agencies, NIST created Special Publication (SP) 800-37 “Guide for the Security Certification and Accreditation of Federal Information Systems.” This whitepaper helps readers understand the relationship between NIST 800-37, FISMA and application security testing.

 
Understanding SaaS Security Questions

Learn what security questions you should be asking SaaS providers and how Veracode addresses these core requirements.