Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Pitching business software assurance

Fortify claims that it has discovered a new process, called software assurance, that will revolutionize enterprise security by allowing for continuous vulnerability scanning


As part of the BSA process, organizations will require that business partners and even their customers are doing their own due diligence in keeping vulnerabilities out of their applications, according to Fortify's espoused vision.

It's no coincidence that the company announced its backing of the BSA concept simultaneous to the release of its new Fortify 360 product line, which is more expansive than the company's previous products in terms of its reach across various stages of applications development.

However, the product was tailored to reflect emerging demands from the firm's customers, some of whom are already mature enough in their development operations to embrace the BSA process, Fortify executives said.

Officials with at least one of the company's customers, online stock trading provider Scottrade, said that they are moving in the direction of BSA, even if they have yet to adopt that nomenclature for their work.

Scottrade and its rivals, including eTrade and other online stock sites, have been among those businesses who have publicly announced significant financial write-offs driven by applications-level attacks on their trading systems.

The key idea is approaching applications security as a process, rather than on a more piecemeal basis, as has been common practice for many firms up until now, said Grant Bourzikas, director of information security at Scottrade.

"To really address the security problem, you have to fix your code; intrusion prevention, Web applications firewalls, and a lot of other security technologies don't address the root cause, which is poor code left vulnerable that forces people to write signatures to protect at the network the level," Bourzikas said. "Of course we use all those products, and we have a traditional layered security approach, but by better securing our code and having this two-pronged effect, we can protect ourselves and our customers a lot better."

Whether or not the market will wrap its arms around the phrase business software assurance or merely view the process as part of a common SDLC (secure development lifecycle) program, the notion of continuous code and applications scanning is one that will continue to catch on with more companies, the executive said.

Yet, as important as any technology is the cultural change that must be affected among developers if the strategy is to succeed, said Bourzikas.

"Tools like this can help with SDLC, but you also have to consider the awareness issue," he said. "People have to better understand all the risks, because no one goes out and tries to write code that is insecure by default, they've been told to write something that works and they meet those requirements. We're hoping to teach our developers on what they need to protect, so in that sense, education is every bit as important."

Matt Hines is a senior writer at InfoWorld.
« PREVIOUS PAGE | 1 | 2 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





MIGRATING TO VISTA
Join Windows Vista Expert, Richard Whitehead as he presents the benefits and challenges of migrating to Windows Vista. Sponsored by Novell

»  Click here to view this Webcast
  The Path to Enterprise Security
This is your comprehensive guide to Enterprise Security. In it you'll find solutions to the most pressing security threats facing you and your company. Learn the latest on insider threats and how to effectively minimize risk within your organization. Sponsored by Nokia

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 10/10/2008

A look back at the week: AMD splits into two, Panasonic sets world record...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist