#MicroFocusCyberSummit
AppSec at High Speed and Scale
Scott Johnson, Fortify GM
AppSec at High Speed and Scale Agility, Integration & Automation - - PowerPoint PPT Presentation
AppSec at High Speed and Scale Agility, Integration & Automation Scott Johnson, Fortify GM #MicroFocusCyberSummit Forward Looking Statements: Legal Disclaimer This document contains forward looking statements This document contains forward
#MicroFocusCyberSummit
Scott Johnson, Fortify GM
This document contains forward looking statements regarding future operations, product development, product capabilities and availability dates. This information is subject to substantial uncertainties and is subject to change at any time without prior notification. Statements contained in this document concerning these matters only reflect Micro Focus's predictions and / or expectations as of the date of this document and actual results and future plans of Micro Focus may differ significantly as a result of, among other things, changes in product strategy resulting from technological, internal corporate, market and other changes. This is not a commitment to deliver any material, code or functionality and should not be relied upon in making purchasing decisions.
2
This document contains forward looking statements
3
5
1000 applications and counting…
6
“I want 5 minute scans with no false positives.”
7
We have seen the AppSec team AND IT IS YOU! (the developer)
9
10
11
12
13
15
16
Integration Automation Agility On-premise / On Demand Fortify Ecosystem Software Security Research
Static Analysis – SCA
Scan and Assess Source Code
Dynamic Analysis – WebInspect
Web Application Vuln Scanning
Runtime Analysis – App Defender
Application Protection & Monitoring
17
RestAPIs
18
https://fortify.github.io/
Bamboo Plugin
19
https://marketplace.atlassian.com/plugins/com.fortify.plugi ns.atlassian.bamboo.sca.bamboo-fortify-sca- plugin/server/overview
VSTS Extension
https://marketplace.visualstudio.com/items?itemName=fortifyvsts.hpe- security-fortify-vsts
Snyk Integration
20
Audit Assistant
21
Auto-train Auto-predict Auto-tag
Unaudited results enter SSC Audited issues arrive in SSC Audit assistant derives anonymous issue metrics and securely sends to scan analytics Classifiers report verified vulnerabilities with up to 98% accuracy
Centralized Translation & Scanning
22
Benefits
Slack Enabled FoD!
23
Security Assistant for Visual Studio
24
Swift Language Support
25
Support within 3 to 6 weeks of Apple updates!
Q118 Q218 28
Fortify Roadmap
Fortify- SCA / SSC / WebInspect / Fortify on Demand
This is a rolling (up to three year) Roadmap and is subject to change without notice
Targeted Available
integration with Sonatype
FoD 18.1
Xcode 9.x, Python 3.x, Xamarin, Scala- Play
Bamboo plugin
On-Premise 18.1
automation
Assistant for Visual Studio, Bamboo plugin
analysis (JS support)
FoD Upcoming
FoD Future ‒ High level themes On-Premise Upcoming
features for: Integration / Automation / Agility
Java 11, Python- Django, Swift 5, Go, Ruby on Rails, centralized scanning and dependency
On-Premise Future FoD 18.2
Python 2 update, Obj-C, .NET MSBuild, SCA logging enhancements, C/C++
4+, REST API improvements, sensor management
#MicroFocusCyberSummit
#MicroFocusCyberSummit