Making software more secure

CAST brings more than 25 years of excellence in software quality to help CIOs measure and maintain secure software with system-level analysis.

  • 7 years ago Posted in
CAST has introduced CAST for Security, a new offering that leverages system-level analysis to strengthen the security of business-critical software. CAST for Security helps organisations optimise application design to protect sensitive data by preventing common software attacks and enforcing architectural constructs known to keep data secure.
Combining technology from the Application Intelligence Platform (AIP) and specific rules for static application security testing (SAST), CAST for Security flags security hot spots that are vulnerable to attack, ensures secure coding practices, eliminates false positives and trends security performance over time.
“Cyber risk and security challenges have moved beyond network-level issues to the application layer. To be successful in this new paradigm, CIOs must adopt a holistic, proactive and design-based approach to securing applications while not overwhelming development teams,” said Olivier Bonsignour, EVP of Product Development at CAST. “As organisations adopt DevOps and Agile methodologies for speed, CAST for Security opens a new line of cyber defence by inserting secure design practices from the beginning of the software development lifecycle, resulting in high-quality, secure apps that can still be delivered in a timely manner.”
Most security tools that analyse source code only look for intrusion vulnerabilities, like SQL injection and cross-site scripting. This approach still leaves business-critical data at risk. CAST for Security uses AIP’s system-level analysis to create an architectural blueprint for applications and immediately identify data call pathways that are vulnerable. This also enables teams to estimate the security debt of critical applications for a more complete picture of software risk.
“We see organisations coordinating security with quality initiatives increasingly overall and also as a part of DevSecOps initiatives; applying system-level code analysis to help secure applications during development is a key aspect,” said Melinda Ballou, Research Director, Agile ALM, Quality and Portfolio Strategies at IDC. “Providing contextualised software analysis to reduce noise and help eliminate false positives that distract from actual software vulnerabilities enable visibility and higher success for security and quality strategies.”
“As a recognised leader in analysing system reliability and resilience in IT software, CAST has always had an established set of security findings,” added Lev Lesokhin, EVP of Strategy and Analytics at CAST. “Over the last two years, a significant part of our customer base has tapped CAST for our security capabilities because it’s much more comprehensive than what is available today. CAST for Security is now packaged and priced as a separate offer to make it easier for our customers to benefit from CAST’s expertise in application security.”
On average, only 48% of digital initiatives meet or exceed business outcome targets, according to...
Humans may do a lot less of the testing themselves in the future, but they will still have to peer...
JFrog has released the findings of an IDC survey indicating developers are spending significantly...
New research from Mendix finds that low-code tools are no longer simply a tactical solution for...
Global study of over 1,300 tech professionals uncovers opportunities for enhanced security training...
Global IT Business-to-Business (B2B) revenues, coming from data centers, IT services and devices,...
Confluent adds Table API support for Apache Flink® making it even easier for developers to use...
Although 85% of total respondents have integrated AI apps into tech stacks in the past year, most...