Offers correlation of multiple proprietary and open source scan engines, as well as context-based risk prioritization in a single report featuring list and topographic views
SAN FRANCISCO Y RAMAT GAN, Israel, June 7, 2022 /PRNewswire/ — Today’s application security (AppSec) teams and developers have long needed a single, integrated view of the interaction, functionality, and vulnerabilities of the dozens of components in today’s typical application to perform full AppSec tests. In response to that need, checkmarxthe global leader in developer-focused Application Security Testing (AST) solutions, today announced the availability of Fusion Checkmarx, a context-aware mapping engine that enables complete visibility into applications, component interactions, and BOMs. Leverage a holistic view of application security analysis results across all stages of the software lifecycle to correlate and prioritize vulnerabilities, guiding remediation of the most critical issues first. Checkmarx Fusion is part of Checkmarx Onethe industry’s most comprehensive application security platform.
“Development teams test tens of millions of lines of code monthly. With the complexity of modern applications, including source code, open source code, infrastructure as code, containers, and more, developers and their AppSec leaders have a need critical visibility of how application components interact,” said Checkmarx Chief Product Officer Razi Sharier. “Working closely with our customers around the world, we know that developers and AppSec teams need a holistic view of the context and prioritization of application vulnerabilities that is missing from AST and ASOC (Assignment Orchestration and Correlation) solutions. application security.) Checkmarx Fusion unifies, prioritizes, and streamlines the remediation of AppSec vulnerabilities, increasing developer efficiency and organizational agility.”
Teams can now “shift left” and incorporate comprehensive AppSec testing and remediation into the development cycle from the creation of the first line of code to the last. Unlike ASOC solutions, Checkmarx Fusion offers multi-engine scan correlation and context-based risk prioritization of scan results across all engines. Checkmarx Fusion empowers AppSec developers and teams with these four pillars:
Visibility: Provides threat modeling by mapping threats into a visual and intuitive graph that contains all the software elements, the cloud resources consumed, and the relationships between them. Checkmarx Fusion extrapolates potential vulnerabilities within two or more scans that might otherwise escape detection.
Correlation– Adds context to silo scanners by combining and correlating the results of static code scans and runtime scans, effectively eliminating false positives
Priorization: Focuses AppSec developers and teams on solving the most critical issues by prioritizing vulnerabilities based on their actual impact and risk.
cloud native– Leverages cloud-native architecture, including microservices, cloud resources, containers, and APIs, while mapping insights from predeployment to runtime
According to Melinda-Carol BallouResearch Director, Application Lifecycle Management (ALM) Program, IDC1“The breadth of capabilities in Checkmarx’s portfolio, spanning SAST, SCA, IAST and IaC security, delivered on a unified platform is an advantage in the highly competitive DevSecOps market space. The platform’s developer approach, coupled with DevOps toolchain integrations and contextualized training can increase developer performance and lighten the burden of security testing, enabling faster delivery of more secure applications.”
Checkmarx Fusion is now available. For more information, visit this page, visit booth #1755 in Moscone South at RSA 2022, or booth #651 at the Gartner Security and Risk Management Summit.
checkmarx is constantly pushing the boundaries of Application Security Testing (AppSec) to make security seamless and simple for developers everywhere, while giving CISOs the confidence and control they need. As the leader in AppSec testing, Checkmarx provides the industry’s most comprehensive AST platform, Checkmarx One, giving developers and security teams unparalleled accuracy, coverage, visibility, and guidance to reduce risk across all components of modern software. , including proprietary code, open source, APIs, and infrastructure as code. More than 1,800 customers, including half of the Fortune 50, trust Checkmarx’s security technology, expert research, and global services to securely optimize development at speed and scale. For more information visit Checkmarx websitereview the Blog or follow the company on LinkedIn.
1 IDC, IDC MarketScape: Worldwide Application Security Testing, Code Analysis, and Software Composition Analysis Vendor Assessment 2022, by Melinda-Carol Ballou, March 2022.
View original content to download media:https://www.prnewswire.com/news-releases/checkmarx-unveils-context-aware-checkmarx-fusion-with-industrys-first-holistic-view-and-cross-component-prioritization-of-application-vulnerabilities- 301562698.html