Fortify Software

Fortify Software

Home Products Fortify On Demand VSM

Fortify on Demand

Vendor Security Management

For most organizations, third-party software represents a significant percentage of installed software and therefore a substantial area of unknown risk. Most software vendors provide customers no visibility into the security state of their products. While improved contracts can provide some remedy after a breach, this backs the software customer into a reactive approach to security. The persistent challenge is getting access to third-party source code, whether commercial off-the-shelf or outsourced development projects.

Fortify on Demand powers a more proactive stance, allowing either vendor or customer to initiate software testing during the procurement or upgrade process, prior to acceptance. Vendor Security Management (VSM) provides a hosted SaaS solution for any third-party development team to test and score the security of their application, review results, and then publish a report back to their customer. Moveover, Fortify on Demand VSM compels vendors to take action to proactively fix the vulnerabilities in their own code.

Fortify on Demand VSM enables internal security teams to verify the security of any third-party software and to ensure that high priority problems get addressed. Fortify on Demand VSM serves as an independent third party and system of record for conducting a consistent, unbiased analysis of the application and providing a detailed tamper-proof report back to the security team.

Sign Up for Fortify VSM
Capabilities
Advantages
Specifications

Award-winning Software Analysis

  • Static analysis of source code and executables
  • Dynamic analysis of web apps of unlimited size, in QA or production, powered by WhiteHat
  • Java, .NET or PHP code
  • Correlated results from static/dynamic in a summary dashboard
  • Consistent, independent five-star rating system
  • Deep details by vulnerability including type, severity rating, line of code, attack surface and time to fix

Quick and Easy Process

  • A highly secure SaaS environment that is automated, scheduled and available on demand
  • User uploads code or URL, and Fortify on Demand does the rest
  • Dynamic analysis at 3 service levels: baseline, standard or premium
  • Human expert review of the results
  • Vendor publishes a tamper-proof report summarizing the security of their application

Neutral, Unbiased System

  • Accurate testing by vendors of their own application
  • Detailed reports for third-party developers on high priority vulnerabilities with repair suggestions
  • Unbiased summary report publication for customer audiences, whether procurement professionals or security practitioners.

Remediation Options

  • Third-party can address security issues using an intuitive online interface, detailed reporting, education guides for each vulnerability
  • Easy upgrade to Fortify 360 to build security into the software development life cycle
 

Contact me about products from Fortify Software

Fortify in the news

Contact Fortify Software

Resources

eNewsletter Sign Up | Software Security Blog | Contact Us | Privacy