|

Watchfire provides software and services to help ensure
the security and compliance of websites. More more than 500
enterprises and government agencies, including AXA Financial,
SunTrust, HSBC, Vodafone, Veterans Affairs and Dell rely on
Watchfire to audit and report on issues impacting their online
business. Watchfire has been the recipient of several industry
honors including the HP/IAPP Privacy Innovation Award, InfoSecurity
Product Guide’s Hot Security Company 2006, Computerworld’s
Innovative Technology Award, and “Recommended” rating by Computer
Reseller News. Watchfire was named by IDC and Gartner as the
worldwide market-share leader in web application vulnerability
assessment software. Watchfire's technology partners include IBM
Global Services, PricewaterhouseCoopers, TRUSTe, Microsoft,
Interwoven, EMC Documentum and Mercury.
Watchfire® AppScan®
Watchfire® AppScan® the worldwide market-share leading web
application security assessment software, offers a solution for all
types of users - application developers to help them build secure
web applications; quality assurance teams to provide security
assurance testing before deployment; and security auditors and
senior management to continually monitor the “live” environment.
PRODUCT FACTSHEET
The AppScan product suite consists of:
- AppScan for Auditors: used to conduct on-going
security audits to validate web application security and
compliance against regulatory and organizational initiatives in
the live environment
- AppScan for Mercury Quality Center™: enables security
testing from within a familiar QA environment, reducing errors
and improves efficiency
- AppScan DE (Developer Edition): integrated with
several major development environments, such as JBuilder,
Websphere, MS Visual Studio.Net and Eclipse, AppScan DE lets
users test web applications early in the development process and
from within their development environment
For Auditors:
Watchfire® AppScan®
Watchfire® AppScan®
is the industry's first and leading web application security testing
suite, and the only one to provide comprehensive remediation tasks
at every level of the application. AppScan analyzes web
applications, tests for security issues and generates actionable
reports and remediation recommendations. AppScan's scanning
capabilities, Zero-Day vulnerability updates, Configuration Wizard
and detailed reporting system all combine to simplify ease of use
for auditors and security professionals, enhance their productivity,
facilitate security compliance and protect the web application
infrastructure.
Benefits:
- Remediation View: shows a comprehensive list of
tasks needed to fix the security issues found by the scan
- Real-time View of Results: shows the Application
Tree and Results List during the scan so users can track
scan progress and promptly take action on important issues
- Customizable Reports: customizable reports for
management, developers, QA engineers and security
professionals, providing users full control of content and
layout
- Industry-standards Support: including the OWASP
Top 10, SANS Top 20 and the WASC standards
- Regulatory Compliance Reporting: generates 31
regulatory compliance templates and reports
For Application Developers
AppScan DE
AppScan DE integrates web application security testing into
several major development environments, such as JBuilder, Websphere,
MS Visual Studio.Net and Eclipse. This enables application
developers to unit test web applications early in the development
process. AppScan DE automates precision security unit testing,
delivers comprehensive defect analysis and offers
environment-specific recommendations for fixing security flaws.
Benefits:
- Build security testing into development to find
vulnerabilities early in the process
- Intelligent fix recommendations improve productivity
- Designed so unit testing of web applications can be
performed quickly and easily within major development
environments (JBuilder, Websphere, Eclipse)
For QA teams
AppScan for Mercury Quality Center
AppScan for Mercury
Quality Center™ helps Quality Assurance teams centralize test
creation and results viewing to facilitate a consistent and
repeatable testing process which reduces errors and improves
efficiency. AppScan for Mercury Quality Center enables all aspects
of web application testing – functional, load and security – to be
managed and run directly from the Quality Center environment. This
comprehensive solution provides you with a lower total cost of
operation, reduced business risk and on-time delivery of secure
applications for a significant return on your technology investment.
Benefits:
- Provides QA teams a single console and environment for
managing all security and quality tests of web applications
- Delivers real-time training on secure testing and coding techniques
- Automates security testing and execution as part of the normal QA run
Watchfire can be found on the web at
www.watchfire.com |