#MicroFocusCyberSummit
Using Automatic and Manual Tests for Static, Dynamic, and Mobile with Fortify on Demand
Rick Smith Product Manager
Dynamic, and Mobile with Fortify on Demand Rick Smith Product - - PowerPoint PPT Presentation
Using Automatic and Manual Tests for Static, Dynamic, and Mobile with Fortify on Demand Rick Smith Product Manager #MicroFocusCyberSummit Agenda Identifying the cost Identifying the tool A quick case study 2 Thinking about the cost 3
#MicroFocusCyberSummit
Rick Smith Product Manager
2
3
Procuring secure software Certifying new releases Securing legacy applications
Demonstrating Compliance Legacy Software In-house Development
5
Monitoring / Protecting Production Software
Open Source Outsourced Commercial
6
Release Frequency Number of Applications
App App
8
Do you need a hammer?
Fortify on Demand
Developers (IDE) Step 1: Develop & check-in code Step 4: Automated Audit Step 3: Start Static Assessment Source control repository Step 2: Scheduled or triggered check-out & build Continuous integration server Fortify SCA Fortify Scan Analytics FoD security expert (Optional) Step 5: Manual Audit Vulnerability Management
Vulnerabiliti es Vulnerabiliti es
Defect management Step 6: Triage, assign & fix vulnerabilities
Bill of materials Known vulnerabilities License risk
Open Source Analysis
18
19
22
23
#MicroFocusCyberSummit