June 19, 2007

HP-SPI deal underscores apps security integration

As attacks on applications-level vulnerabilities increase, more enterprises are integrating security testing apps into their software development -- often via acquisition

Hewlett Packard's acquisition of Web applications security specialist SPI Dynamics on June 19 illustrates a growing demand among enterprise customers to have vulnerability-scanning tools integrated into their software development platforms.

Following closely behind IBM's June 6 acquisition of Watchfire, one of Atlanta-based SPI's closest rivals in the Web applications and software code-scanning space, the HP buyout highlights the rapidly emerging trend toward integration of security testing tools into the software development process.

HP, which acquired software development giant Mercury Interactive for $4.5 billion in cash in July 2006 in a move that greatly expanded its interests in the area, said that it plans to blend SPI's business and its 140 person staff into the software unit at its Technology Solutions Group, the division responsible for its server and storage products, as well as its IT consulting services.

In response to the growing threat of attacks on applications-level vulnerabilities, the company said, more customers than ever before are building security testing requirements into their development projects.

By folding applications security testing into its existing portfolio of tools, HP officials said, the company has added an increasingly strategic piece of the overall software development puzzle.

"This adds a new chapter to the applications side of the house; we think of applications and [IT] operations working together, and this adds the piece of security assessment from early on in the [software development] lifecycle all the way through to production," said Jonathan Rende, vice president of products for the Quality Management Software group at HP.

"This is a new dimension of that, that is so complementary because there is a whole set of users who are getting involved in security assessment in the lifecycle," Rende said on a conference call with media and analysts. "There are security experts who determine policies and prepare applications before they go live, but then there are also the developers and quality assurance professionals who need to ensure security before the applications go live."

In a research report published by market analysis firm Gartner in May 2007, industry experts said that by 2009, some 80 percent of major software development lifecycle vendors would offer source code security scanning tools as part of their platforms.

The company said that further that 60 percent of IT organizations will have made vulnerability detection an integral part of their development process by 2010.

HP's move to buy SPI and IBM's acquisition of Watchfire provide tacit evidence that those predictions are already coming to pass, said Joseph Feiman, the Gartner analyst who authored the report.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.