About Auditing

When Fortify Static Code Analyzer scans sourceClosed code, all of its discoveries are presented as potential vulnerabilities, not actual vulnerabilities. Because every applicationClosed is unique and all functionality runs within a particular context understood best by the development team, no technology can fully determine if a suspect behavior should be considered a vulnerabilityClosed without direct developer confirmation.

Issue audits, whether performed in Fortify Software Security Center or Audit Workbench, or by Audit AssistantClosed, accomplish the following:

Fortify Software Security Center uses issue templates to categorize and display issues.

See Also

Setting the Strategy for Resolving Issue Audit Conflicts