Predefined policies

In Configuration > Test policy and optimization, the drop-down lets you select a predefined or recently used policy. The table below lists the predefined policies, which provide a range of useful policies for common requirements.
Note: Policies marked * are deprecated and do not appear in the drop-down selector. They are still available in the Policies folder:
C:\Program Files (x86)\HCL\AppScan Standard\Policies

Policy name

Description

Default

Includes all tests except invasive and port listener tests.

Application-Only

Includes all application level tests except invasive and port listener tests.

Infrastructure-Only

Includes all infrastructure level tests except invasive and port listener tests.

Third-Party-Only

Includes all third-party level tests except invasive and port listener tests.

Invasive

Includes all invasive tests (tests which might affect the server's stability).

Complete

Includes all AppScan® tests.

Production Site

Excludes invasive tests that might damage the site, or tests that might result in Denial of Service to other users.
Note: For more information about scanning a live site, see Scanning live production environments.
OWASP Top 10 - 2021 Includes all tests for the latest top 10 vulnerabilities categories mapped by OWASP.
OWASP Top 10 API Security Risks - 2023 Includes all tests for the latest top 10 API vulnerability categories mapped by OWASP.
Web Services* Includes all REST and SOAP related tests except invasive and port listener tests.
The Vital Few* Includes a selection of tests that have a high probability of success. This can be useful for evaluating a site when time is limited.
Developer Essentials* Includes a selection of application tests that have a high probability of success. This can be useful for evaluating a site when time is limited.