CSC has unveiled a new offering called AppSEC on Demand that enables organizations to test the security of software applications and build security into the software development lifecycle.
AppSEC on Demand is hosted in a secure environment that meets both U.S. federal and commercial regulatory requirements, CSC said.
The new CSC application security testing-on-demand offering allows organizations to test the secure status of their software without incurring extra technology and infrastructure overheads, Andrew Kellett, an Ovum principal analyst, said.
The solution combines proven software, certified experts and rigorous processes to minimize risk for organizations by offering the capability to perform security testing on all applications for every release, from every source and on every platform, CSC claims.
CSC conducts the tests on the application code, verifies the results and presents a detailed report of vulnerability findings to its clients with recommendations on what can be fixed with procedural changes and what can be fixed with code changes.
Tests include static analysis of applications in non-run-time environments, dynamic assessments on live applications, and security assessments on mobile applications
“Adversaries never sleep, and with AppSEC on Demand, we continually monitor around-the-clock our clients’ application performance and then deliver insights to decision-makers for cost-effective hardening of their code,” said Samuel Visner, CSC’s vice president and general manager for cybersecurity.
“Moreover, for our public sector customers, we run AppSEC in secured data centers and securely interface with government networks, providing the ability to service sensitive environments,” Visner added.
To deliver this offering to clients, CSC has teamed with HP to host its Fortify application security products within CSC’s global network of security operations centers, integrating them with CSC’s security information and event management and global threat intelligence platforms.