Enhance AST tool effectiveness with continuous tuning and false positive analysis.
AppSec resource will take full responsibility of AST tools from an administration perspective. This includes user management and related configuration of the AST tools.
To show the ROI of the AST tools, AppSec resource will develop and enhance SLAs and KPIs to measure the tools utilization and its impact on the organization.
Develop a triaging process to address the findings yielded from AST tools. This will give a well-defined structure of how the organization will handle the findings from AST tools.
AppSec resource will conduct scans, perform false positive analysis, and create reports of AST tools findings. This will help mature the tools and prioritize findings that are important to stakeholders.