Veracode Simplifies Security Policy Management for Organisations Grappling with Mobile Applications and the Consumerisation of IT
New Veracode Policy Manager Allows Enterprises to Move Rapidly from Ad-hoc Testing to Enforceable Security Programs and Policies for Their Entire Software Application Portfolio
LONDON, U.K., -- 21 June, 2011 – The consumerisation of IT can bring new workforce efficiencies, as well as potentially devastating enterprise security and compliance risks. As organisations grapple with the new era of mobile device management, a one-size-fits-all approach to application security policy management and compliance isn’t sufficient.
Today, Veracode, Inc., provider of the world’s only independent, cloud-based application risk management platform, announces a more effective approach with the launch of its new Veracode Policy Manager.
Veracode Policy Manager allows enterprises to move rapidly from ad-hoc testing to proven and enforceable security programs and policies for their entire software application portfolio, including mobile. Veracode currently provides application security verification across primary mobile platforms - RIM’s BlackBerry operating system (OS), Windows Mobile, Google’s Android OS and Apple iOS.
A cloud-based service, Veracode Policy Manager provides CISOs with a dashboard that offers a centralised view of their portfolio of internal and third-party applications with details on how each application is performing from a policy perspective. Veracode Policy Manager’s easy-to-use interface offers specific compliance requirement tracking capabilities and enables users to tick through a series of best practice-based or customisable drop-down menus that identify appropriate security policy options, including recommended remediation times based on the criticality of the flaw, criticality of the application and established CISO requirements.
“Mobile adoption and related application vulnerabilities are pushing organisations to think more seriously about software security. The reality is that mobile apps are no different from other enterprise apps from a security policy perspective. However, many organisations, even those that are serious about application risk management, are still questioning what those security policies should be, and how to enforce and report on them,” said Maria Cirino, chairperson, Veracode Board of Directors, and managing director, .406 Ventures.
Policy Manager Makes Effective Governance Programs Possible
Veracode Policy Manager provides the ability to customise application security acceptance criteria (or use Veracode best practices), enforce required scan type and frequency, set “fix by” dates on flaws and set default global or per-application policies.
Specific features of Veracode Policy Manager include:
- Application Policy Dashboard: Centralised dashboard for applying policies, assigning business owners, adding new applications and tracking policy compliance across application inventory
- Policy Editor: Interface to defining custom policies based on standards (e.g., OWASP/SANS Top 25), flaw type (CWE), severity and Veracode rating with capability to specify assessment frequency, acceptable remediation timeframes and grace periods
- Policy Control Reports: Detailed reports depicting status against all controls specified within applicable policy, provides snapshot of compliance on a per-application basis
- Notification Workflow: Support for automated notifications to business owners regarding policy assignment, testing requirements and compliance status
Available to all current Veracode customers, Veracode Policy Manager offers CISOs greater risk management control across their entire application portfolio. It enables organisations to better adhere to, and enforce and report on, established policies associated with applications’ business criticality and portfolio risk tolerance. It also enables CISOs to identify variances between known risk tolerance and those internally or third-party-developed applications that are the farthest from compliance. Those variances can then be used to influence the establishment of benchmarks across the organisation’s developer and vendor community.
“Veracode Policy Manager was developed with CISOs in mind. We simplify the governance process and put control in the hands of the CISO, helping them to gain a centralised view of their portfolio from a policy performance perspective while supporting more well-informed discussions with senior management related to risk tolerance and compliance,” continued Cirino.
Along with the launch of Veracode Policy Manager, the company is offering access to two new resources for organisations seeking additional guidance with determining, setting and enforcing the appropriate security policies for their software portfolio.
• “Policy-Driven Software Security From Ad-Hoc Testing to a Programmatic Approach,” available here: http://info.veracode.com/policy-wp-june-2011.html
• “Understanding the Risks of Mobile Applications,” available here: http://info.veracode.com/Whitepaper-2011-Mobile.html
Veracode is the only independent provider of cloud-based application intelligence and security verification services. The Veracode platform provides the fastest, most comprehensive solution to improve the security of internally developed, purchased or outsourced software applications and third-party components. By combining patented static, dynamic and manual testing, extensive eLearning capabilities, and advanced application analytics, Veracode enables scalable, policy-driven application risk management programs that help identify and eradicate numerous vulnerabilities by leveraging best-in-class technologies from vulnerability scanning to penetration testing and static code analysis. Veracode delivers unbiased proof of application security to stakeholders across the software supply chain while supporting independent audit and compliance requirements for all applications no matter how they are deployed, via the web, mobile or in the cloud. Veracode works with customers in more than 80 countries worldwide including Global 2000 brands such as Barclays PLC and Computershare as well as the California Public Employees’ Retirement System (CalPERS) and the Federal Aviation Administration (FAA). For more information, visit www.veracode.com, follow on Twitter: @Veracode or read the ZeroDay Labs blog.
# # #
Copyright © 2011 Veracode, Inc. All Rights Reserved. All other brand names, product names, or trademarks belong to their respective holders.
t. 07766 257776
This press release was distributed by ResponseSource Press Release Wire on behalf of Hothouse Communications in the following categories: Business & Finance, Computing & Telecoms, for more information visit https://pressreleasewire.responsesource.com/about.