Fortify WebInspect Policies

A policy is a collection of vulnerability checks and attack methodologies that Fortify WebInspect deploys against a Web application. Each policy is kept current through SmartUpdate functionality, ensuring that scans are accurate and capable of detecting the most recently discovered threats.

Fortify WebInspect contains the following packaged policies that you can use to determine the vulnerability of your Web application.

Note: This list might not match the policies that you see in your product. SmartUpdate might have added or deprecated policies since this help was produced.

Best Practices

The Best Practices group contains policies designed to test applications for the most pervasive and problematic web application security vulnerabilities.

By Type

The By Type group contains policies designed with a specific application layer, type of vulnerability, or generic function as its focus. For instance, the Application policy contains all checks designed to test an application, as opposed to the operating system.

Custom

The Custom group contains all user-created policies and any custom policies modified by a user.

Hazardous

The Hazardous group contains a policy with potentially dangerous checks, such as a denial-of-service attack, that could cause production servers to fail. Use this policy against non-production servers and systems only.

Deprecated Checks and Policies

The following policies and checks are deprecated and are no longer maintained.