Picking the Right Assessment Types for your Application Security Program

Logo
Presented by

Chris Kirsch, Director, Product Marketing at CA Veracode

About this talk

Most companies start their application security program with a manual penetration test of their most business-critical applications. While this type of assessment covers a lot of ground, it’s not as scalable and repeatable as automated scanning technologies. As your program matures, you’ll have to branch out into more automated technologies. This talk will review the merits of static analysis, dynamic analysis, software composition analysis, and penetration testing, indicating which technologies make sense in your specific situation as you mature your application security program.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (396)
Subscribers (31059)
Veracode is intelligent software security. The Veracode Software Security Platform continuously finds flaws and vulnerabilities at every stage of the modern software development lifecycle. Prompted by powerful AI trained by trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means. Learn more at www.veracode.com