Latest Comments
"its gud"
by Mahesh | Dec 3, 2008 5:59 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Fortify Source Code Analysis

  • Email a Friend
  • Print Page
Fortify Source Code Analysis
Product Info
Supplier:
Product Rating
Features:  5
Ease of Use:  4
Performance:  3
Documentation:  5
Support:  5
Value for Money:  5
Overall Rating:  Overall Rating
 
For: Scans code prior to implementation to catch holes before they happen.
Against: For the non-full-time programmer, the utility might be a bit tricky.
Verdict: A great CASE program, which should be used as part of any system development lifecycle.
This ties tightly to the PCI-DSS standards, which require code reviews, and also should be part of a SDLC (system development life cycle). The use of source code analysis is, of course, the best way to spot flaws and, unlike most of the products we tested, is not a black box test.

Source Code Analysis (SCA) suite supports many languages — including ASP.NET, C/C++, C#, ColdFusion, Java, JSP, PL/SQL, T-SQL, XML, VB.NET and other .NET languages.

Source Code Analysis (SCA) suite also supports several development environments, such as Microsoft Visual Studio, Eclipse, WebSphere Application Developer and IBM Rational Application Developer. Source Code Analysis Suite can be installed on a variety of operating systems, including Windows, Mac, Solaris, Linux, AIX and HPUX.

The installation of the suite was simple and the utility automatically downloads updates during part of the installation process. The process was a bit time-consuming as the process configured the system.

The application installation performs most of the configuration without the need for user intervention. All in all, the installation process was among the simplest in this Group Test.

The suite arrived with a guide for the initial installation in hard copy. A PDF version of the document is also available. The PDF files are not indexed and searchable, so the PDF needs to be scanned manually.

Support is offered through phone and a password-protected web portal, and also through email. In addition, the standard price allows for quarterly updates for the latest security tests for code review. Phone support is available 6 a.m. to 6 p.m. Pacific Standard Time.

The pricing for Source Code Analysis (SCA) suite is $1,200 per developer. This prices Source Code Analysis (SCA) suite at the low end of the spectrum. For a feature rich CASE environment, this price is definitely a value.

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
Ready to use
SC Magazine - comments icon Posted by abhay diwaleSep 16, 2008 8:17 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers