Veracode Policy Manager allows enterprises to move rapidly from ad-hoc testing to proven and enforceable security programs and policies for their entire software application portfolio, including mobile. Veracode currently provides application security verification across primary mobile platforms - RIM’s BlackBerry operating system (OS), Windows Mobile, Google’s Android OS and Apple iOS.
A cloud-based service, Veracode Policy Manager provides CISOs with a dashboard that offers a centralized view of their portfolio of internal and third-party applications with details on how each application is performing from a policy perspective. Veracode Policy Manager’s easy-to-use interface offers specific compliance requirement tracking capabilities and enables users to tick through a series of best practice-based or customizable drop-down menus that identify appropriate security policy options, including recommended remediation times based on the criticality of the flaw, criticality of the application and established CISO requirements.
“Mobile adoption and related application vulnerabilities are pushing organizations to think more seriously about software security. The reality is that mobile apps are no different from other enterprise apps from a security policy perspective. However, many organizations, even those that are serious about application risk management, are still questioning what those security policies should be, and how to enforce and report on them,” said Maria Cirino, chairperson, Veracode Board of Directors, and managing director, .406 Ventures.
Policy Manager Makes Effective Governance Programs Possible
Veracode Policy Manager provides the ability to customize application security acceptance criteria (or use Veracode best practices), enforce required scan type and frequency, set “fix by” dates on flaws and set default global or per-application policies.
Specific features of Veracode Policy Manager include:
Available to all current Veracode customers, Veracode Policy Manager offers CISOs greater risk management control across their entire application portfolio. It enables organizations to better adhere to, and enforce and report on, established policies associated with applications’ business criticality and portfolio risk tolerance. It also enables CISOs to identify variances between known risk tolerance and those internally or third-party-developed applications that are the farthest from compliance. Those variances can then be used to influence the establishment of benchmarks across the organization’s developer and vendor community.
“Veracode Policy Manager was developed with CISOs in mind. We simplify the governance process and put control in the hands of the CISO, helping them to gain a centralized view of their portfolio from a policy performance perspective while supporting more well-informed discussions with senior management related to risk tolerance and compliance,” continued Cirino.
Additional Resources
Along with the launch of Veracode Policy Manager, the company is offering access to two new resources for organizations seeking additional guidance with determining, setting and enforcing the appropriate security policies for their software portfolio.
Veracode is the only independent provider of cloud-based application intelligence and security verification services. The Veracode platform provides the fastest, most comprehensive solution to improve the security of internally developed, purchased or outsourced software applications and third-party components. By combining patented static, dynamic and manual testing, extensive eLearning capabilities, and advanced application analytics Veracode enables scalable, policy-driven application risk management programs that help identify and eradicate numerous vulnerabilities by leveraging best-in-class technologies from vulnerability scanning to penetration testing and static code analysis . Veracode delivers unbiased proof of application security to stakeholders across the software supply chain while supporting independent audit and compliance requirements for all applications no matter how they are deployed, via the web, mobile or in the cloud. Veracode works with customers in more than 80 countries worldwide including Global 2000 brands such as Barclays PLC and Computershare as well as the California Public Employees’ Retirement System (CalPERS) and the Federal Aviation Administration (FAA). For more information, visit www.veracode.com, follow on Twitter: @Veracode or read the ZeroDay Labs blog.
Copyright © 2011 Veracode, Inc. All Rights Reserved. All other brand names, product names, or trademarks belong to their respective holders.
Liz Campbell
fama PR
phone: +1 617-986-5009
email:
veracode@famapr.com