running a comprehensive application security program with checkmarx and threadfix 

20
© 2016 Denim Group – All Rights Reserved Running a Comprehensive Application Security Program with Checkmarx and ThreadFix September 15, 2016 1 Matt Rose Global Director of Application Security Strategy, Checkmarx Dan Cornell CTO, Denim Group

Upload: denim-group

Post on 15-Apr-2017

259 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Running a Comprehensive Application Security Program with

Checkmarx and ThreadFixSeptember 15, 2016

1

Matt$RoseGlobal'Director'of'Application'Security'Strategy,Checkmarx

Dan$CornellCTO,'Denim'Group

Page 2: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Agenda

• State of Application Security• Checkmarx Overview• ThreadFix Overview• ThreadFix / Checkmarx Integration

2

Page 3: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

Checkmarx Secure SDLC with ThreadFix

Matt Rose – Global Director Application Security Strategy, Checkmarx

Dan Cornell – CTO, Denim Group

Page 4: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

WHAT ACTUALLY MATTERS IN APPLICATION SECURITY TESTING?

Page 5: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

SECURITY PROFESSIONALS WANT TO TEST, DEVELOPERS WANT TO CODE

Proprietary and Confidential | All Rights Reserved

Page 6: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

Test

CHECKMARX CREATES YOUR SDLC A SECURE SDLC

Ticketing/Bug

Tracking Systems

Build(self test)

ReleaseDecision

Backlog

Design

Develop

Security GateScanning

Developer IDE Plugins

Trending and Reporting

Data Export API

Scan Automation

SVN TFS

CLI, Web Services API

TFS

Bamboo

Web Service API

CLI

Build Servers

Proprietary and Confidential | All Rights Reserved

Page 7: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

The Software you sell or develop for your customers needs to be secure. Be proactive and use your Application Security program as a differentiatorThis leads to:

Less vulnerabilitiesLower costsFar more secure applicationsSatisfied Customers

BOTTOM LINE

Proprietary and Confidential | All Rights Reserved

Page 8: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

ThreadFix Overview

• Create a consolidated view of your applications and vulnerabilities

• Prioritize application risk decisions based on data

• Translate vulnerabilities to developers in the tools they are already using

3

Page 9: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

ThreadFix Overview

4

Page 10: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Create a consolidated view of your

applications and vulnerabilities

5

Page 11: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Application Portfolio Tracking

6

Page 12: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Easy Checkmarx CxSAST Import

Page 13: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Vulnerability Consolidation

8

Page 14: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Prioritize application risk decisions based on

data

9

Page 15: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Vulnerability Prioritization

10

Page 16: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Prioritization with Hotspot

Page 17: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Reporting and Metrics

12

Page 18: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Translate vulnerabilities to developers in the

tools they are already using

13

Page 19: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Defect Tracker Integration

14

Page 20: Running a Comprehensive Application Security Program with Checkmarx and ThreadFix 

© 2016 Denim Group – All Rights Reserved

Questions and Contact

ThreadFixwww.threadfix.it

Checkmarxwww.checkmarx.com