Fortify delivers software lifecycle assurance

New tools to guard software throughout lifecycle

Written by Dave Bailey

Enterprise application vendor Fortify Software today released a comprehensive software assurance suite, which it claims offer application testing unparalleled capabilities.

Fortify 360 can be deployed to analyse code development throughout the software lifecycle: planning, coding, testing, deployment and the phase which is the major part of the cycle, maintenance.

The system be used to correct potential software flaws, and provides a portal for reporting and managing software throughout its entire lifecycle.

“You’d deploy Fortify 360 at any time throughout the coding cycle. For instance you can deploy the runtime component of the system, the runtime analyser, and if you see that the most frequent attack against your application is say, SQL injection hacks, you can guide your team to fix that problem in the code," said Fortify’s product development director Rob Rachwald.

Historically, security weak spots have been shielded by firewalls, with vulnerabilities detected by penetration testing, said Rachwald: "What you should be doing is fixing flaws from the inside-out, rather than the outside-in."

Fortify 360 would allow companies to ingrain software assurance into business processes, "seamlessly connecting security, software development and C-level business management teams," added Rachwald.

Fortify’s 360 includes an analysis module which checks applications at three levels: firstly, there is static analysis of the code itself; then analysis of the applications when they are running during quality assurance testing; and finally real-time monitoring when they have been deployed.

Rachwald suggested that Fortify 360 helps firms reign-in security spending. Hitherto, security costs have risen "year after year, but the number of flaws goes up likewise. You’d have thought that the more you spend, the fewer flaws you have, but we’re not seeing that.”

Fortify 360 also contains an audit workbench for correlating and prioritising flaws, so that the high risk problems can be dealt with first. There is also Instant Remediation Capability and Secure Collaboration modules, all overseen by Fortify Manager, a centralised security dashboard and control centre, which provides reporting, governance and policy management tools for tracking multiple application.

As well as the intrinsic security code metrics in Fortify 360, the package also provides developers with quarterly threat intelligence updates generated by Fortify Security Research Group researchers. These rule packs address why real world systems fail and advised customers how to best counter impending threats.

See also:

reader comments

related articles

oracle logo

Oracle swoops for app testing tools

Oracle is to buy Empirix to boost its web app testing muscle 27 Mar 2008

 

IT unaware of SOA risks

SOA is making headway but few in IT appreciate the risks involved 19 Mar 2008

Monitoring tool takes care of business

Network Monitor 7.0 is a good choice for firms looking for a no-nonsense troubleshooter 24 Jan 2008

New data loss risk for app testers

Compuware research shows firms are exposing customer data during application testing 08 Jan 2008

Software aids delivery of web apps

Interwoven has updated its CAP tool to handle increasingly complex web environments 01 Nov 2007

HP offers security as a service

Updates are made to HP's Application Security Center software. 28 May 2008

Bug exposed in web security standard

VBAAC flaw could affect hundreds of thousands of sites 10 Jun 2008

Sloppy developers blamed for SQL attacks

Security not being built-in to applications, warns Fortify 01 May 2008

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories