start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

Introduction

In a recent Technical Review of HCL AppScan, analyst firm Enterprise Strategy Group (ESG) evaluated and analyzed how AppScan helps developers to continuously secure applications. ESG also evaluated how AppScan can easily be integrated into CI/CD pipelines and support DevSecOps initiatives, to provide organizations with continuous application security at scale.  

ESG’s Methodology 

To thoroughly evaluate AppScan’s application security testing capabilities, ESG followed the general steps that are outlined below: 

  1. ESG defined and associated security policies with an applicationusing HCL AppScan on Cloud’s user interface.  
  2. Then, ESG associated security policies with the application.  
  3. Next, ESG evaluated AppScan’s scan and analyze capabilities, by integrating AppScan into a DevSecOps toolchain 
  4. After evaluating AppScan’s “scan and analyze” capabilities, ESG created a manual dynamic scan and reviewed scan results using the AppScan console.  
  5. Finally, ESG evaluated AppScan’s reporting capabilities 

AppScan’s Impact on DevSecOps  

ESG found that AppScan integrated into four main aspects of DevSecOps:  apps

  • Policy definition, where security and regulatory professionals define and associate policies with an application.  
  • Scan and analyze, when developers use static analysis to “shift security left,” so that they can identify vulnerabilities in code early in their CI/CD pipelines. Dynamic and interactive testing similarly help developers to identify vulnerabilities in running applications.  
  • Vulnerability Remediation, the process that permits developers to review and fix vulnerabilities. ESG found that AppScan’s machine learning accelerated remediation by grouping and prioritizing related vulnerabilities and by identifying potential fixes and fix locations in source code.  
  • Reporting, a key component of the DevSecOps process, where security and regulatory professionals and organizational management can continuously monitor their security and compliance progress.  

You can review all of ESG’s key findings- including benefits that you can achieve by incorporating AppScan into a DevSecOps model- by downloading the complimentary report now.  

Why Application Security Matters to You  

In the closing “Why This Matters” section of its report, ESG summarized the benefits of an effective Application Security Testing program, which I’ve captured verbatim below:  

Integrating and automating application security testing into the DevSecOps methodology enables the identification and correction of cybersecurity vulnerabilities earlier in the application development lifecycle, which enhances security and increases efficiency. It also helps to alleviate challenges faced by skilled cybersecurity teams, which are often much smaller than development teams, as they try to keep up with the increasing pace DevSecOps demands. 

ESG validated that HCL AppScan simplified and accelerated application security testing. With just a few clicks, ESG defined security policies and configured AppScan to test our application for a set of security vulnerabilities and compliance with benchmarks and regulations. ESG found configuring and running on-demand scans to be just as quick and easy, and results from static and dynamic analysis were presented quickly in a concise and consistent interface. 

To Learn More

In addition to downloading ESG’s complete reportyou can watch my companion video with ESG analyst Dave Gruber, where Dave and I spotlight the elements of a truly state-of-the-art Application Security Testing solution.  

Comment wrap

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.

Secure DevOps | November 27, 2024
The Hidden Cost of Security Fixes for Software Developers
Developers spend up to 19% of their time on security tasks, costing companies $28K per developer annually. Learn how to reduce this burden and improve your application security posture with HCL AppScan.
Secure DevOps | October 29, 2024
HCL AppScan 360º v1.4.0: Redefining AppSec with Powerful New Features
Explore HCL AppScan 360º v1.4.0 with VM installation, GitHub integration, GenAI AutoFix, and enhanced DAST/SAST features for seamless security management.
Secure DevOps | October 28, 2024
DAST and SCA Capabilities: Latest Updates in HCL AppScan on Cloud
Discover the latest DAST, SCA, and integration updates in HCL AppScan on Cloud, enhancing application security and streamlining development workflows.