Predefined policies

In Configuration > Test policy and optimization, the drop-down lets you select a predefined or recently used policy. The table below lists the predefined policies, which provide a range of useful policies for common requirements.
Note: Policies marked * are deprecated and do not appear in the drop-down selector. They are still available in the Policies folder:
C:\Program Files (x86)\HCL\AppScan Standard\Policies

Policy name

Description

Note: Standard exclusion: All predefined test policies including the Complete test policy excludes the following tests by default:
  • Outdated tests, such as old CVEs or outdated third-party tests and
  • Disruptive tests that might slow down AppScan's performance, such as port listener tests.

Default

Includes all tests except invasive tests (tests affecting server stability).

Application-Only

Includes all application level tests except invasive tests.

Infrastructure-Only

Includes all infrastructure level tests except invasive tests.

Third-Party-Only

Includes all third-party level tests except invasive tests.

Invasive

Includes all invasive tests (tests that might affect the server's stability).

Complete

Includes all tests.

Production Site

Excludes invasive tests that might damage the site, or tests that might result in Denial of Service to other users.
Note: For more information about scanning a live site, see Scanning live production environments.
OWASP Top 10 - 2021 Includes all tests for the latest top 10 vulnerabilities categories mapped by OWASP.
OWASP Top 10 API Security Risks - 2023 Includes all tests for the latest top 10 API vulnerability categories mapped by OWASP.
Web Services* Includes all REST and SOAP related tests except invasive tests.
The Vital Few* Includes a selection of tests that have a high probability of success. This can be useful for evaluating a site when time is limited.
Developer Essentials* Includes a selection of application tests that have a high probability of success. This can be useful for evaluating a site when time is limited.