#MicroFocusCyberSummit
Application Security as a Service: Start Your Application Security Initiative in Less than a Day
David Harper Practice Principal – Fortify on Demand
Application Security as a Service: Start Your Application Security - - PowerPoint PPT Presentation
Application Security as a Service: Start Your Application Security Initiative in Less than a Day David Harper Practice Principal Fortify on Demand #MicroFocusCyberSummit Agenda The Application Security Problem Security Gate Secure DevOps
#MicroFocusCyberSummit
David Harper Practice Principal – Fortify on Demand
3
5
Security incidents from exploits against defects in the design or code of software.2
12017 Application Security Research Update” by the HPE Software Security Research team, 2017 2U.S. Department of Homeland Security’s U.S. Computer Emergency Response Team (US-CERT)
Percentage of applications containing at least one critical or high vulnerability.1
6
Release Frequency Number of Applications
2020+
App App
marketing related functionality
small boutique consultancies
timescales
functional requirements
customer relationship
customer and the brand
applications, Mobile applications, Cloud applications
governance
many applications you have? Commissioned by the business Capturing personal data is the norm Applications are proliferating
Applications are being driven by the business not IT
Securing outsourced, 3rd party and open source code Difficult to train and retain AppSec experts, developers Lack of resources and expertise Growing number of applications and attacks Rapid release cycles and increasing pressure to push apps into production faster Compliance requirements
Key Requirements
approaches
to market
hardware/software to install
and retain a team of application security experts
all applications
approach
Identify and fix application security issues before application goes into production
Implement solution rapidly Cost Effective
Security Testing Service
Security Gate
Cloud-based Application Security Testing Platform
Launch your application security initiative in < 1 day
Scale to test all applications in your
security results
Desktop…
party, commercial applications
Source: https://medium.com/data-ops/how-software-teams-accelerated-average-release-frequency-from-three-weeks-to-three-minutes-d2aaa9cca918
(anticipated)
Means different things to different people DevOps aims to bring applications to market rapidly through:
delivering a service
Security is perceived an inhibitor
Defining Characteristics
Merging of Dev & IT Ops
(working together)
Increased Agility/Flexibility Continuous Integration Automation Lean Faster Time-to- Development Modern Development More Robust Dynamic Apps
Best way to deliver secure applications is to build security in
Address security early
Security gates still have their place
critical releases
Add compensating controls
Addressing the challenge
Initiate Define Implement Design Develop Test Operate Governance Construction Operations Verification
Strategy & Metrics Policy & Compliance Education & Guidance Threat Assessment Security Requirements Secure Architecture Design Review Code Review Security Testing
Issue Management Environment Hardening
Operational Enablement
Powered by Industry leading Fortify products
– SAST
– SAST
– DAST
– RASP
Available on Demand
Fully integrated in the DevOps Toolchain
Application Security Testing on Demand
Secure DevOps eLearning SAST Component Analysis SAST Baseline SAST in IDE SAST Continuous Integration DAST RASP
Role-based Training
eLearning
Role-based Secure DevOps Training
Use secure components
Component Analysis with Sonatype
Full test with Fortify SCA
Results validation
Manual audit by Security Expert
Baseline Static Application Security Testing
Eclipse or Visual Studio Plug-in
code as the developer types
assessment but catches a significant subset of vulnerabilities.
FoD IDE initiated automated scan option for non-supported languages
Real-time light-weight analysis of code in IDE
Jenkins Plug-in
using Fortify Scan Analytics
policy
new security vulnerabilities into Jira.
Visual Studio TFS integration also available Command-line option for
SAST as part of Continuous Integration
Baseline DAST DAST for security critical releases Use DAST in production
Dynamic Application Security Testing
Core component of your infrastructure
process
Compensating Control
application
behavior within application
Integrated with Fortify
assessment findings
Runtime Application Self-protection
Puts security in control
Fortify on Demand addresses the key customer challenges
Proven approach to reduce application security risk Fast enough for most application developments today
27
28
#MicroFocusCyberSummit
#MicroFocusCyberSummit