Fortify delivers software lifecycle assurance

New tools to guard software throughout lifecycle

Written by Dave Bailey

Enterprise application vendor Fortify Software today released a comprehensive software assurance suite, which it claims offer application testing unparalleled capabilities.

Fortify 360 can be deployed to analyse code development throughout the software lifecycle: planning, coding, testing, deployment and the phase which is the major part of the cycle, maintenance.

The system be used to correct potential software flaws, and provides a portal for reporting and managing software throughout its entire lifecycle.

“You’d deploy Fortify 360 at any time throughout the coding cycle. For instance you can deploy the runtime component of the system, the runtime analyser, and if you see that the most frequent attack against your application is say, SQL injection hacks, you can guide your team to fix that problem in the code," said Fortify’s product development director Rob Rachwald.

Historically, security weak spots have been shielded by firewalls, with vulnerabilities detected by penetration testing, said Rachwald: "What you should be doing is fixing flaws from the inside-out, rather than the outside-in."

Fortify 360 would allow companies to ingrain software assurance into business processes, "seamlessly connecting security, software development and C-level business management teams," added Rachwald.

Fortify’s 360 includes an analysis module which checks applications at three levels: firstly, there is static analysis of the code itself; then analysis of the applications when they are running during quality assurance testing; and finally real-time monitoring when they have been deployed.

Rachwald suggested that Fortify 360 helps firms reign-in security spending. Hitherto, security costs have risen "year after year, but the number of flaws goes up likewise. You’d have thought that the more you spend, the fewer flaws you have, but we’re not seeing that.”

Fortify 360 also contains an audit workbench for correlating and prioritising flaws, so that the high risk problems can be dealt with first. There is also Instant Remediation Capability and Secure Collaboration modules, all overseen by Fortify Manager, a centralised security dashboard and control centre, which provides reporting, governance and policy management tools for tracking multiple application.

As well as the intrinsic security code metrics in Fortify 360, the package also provides developers with quarterly threat intelligence updates generated by Fortify Security Research Group researchers. These rule packs address why real world systems fail and advised customers how to best counter impending threats.

Tags:

Further reading

Oracle swoops for app testing tools

Oracle is to buy Empirix to boost its web app testing muscle   More...

IT unaware of SOA risks

SOA is making headway but few in IT appreciate the risks involved   More...

Monitoring tool takes care of business

Network Monitor 7.0 is a good choice for firms looking for a no-nonsense troubleshooter   More...

New data loss risk for app testers

Compuware research shows firms are exposing customer data during application testing   More...

Related articles

Bug exposed in web security standard

VBAAC flaw could affect hundreds of thousands of sites   More...

Hackers attack MySpace and Facebook

Buffer overflow hacks target social networking sites   More...

Sloppy developers blamed for SQL attacks

Security not being built-in to applications, warns Fortify   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement