应用程序安全测试和风险管理
AppScan Enterprise 通过一个提供了治理、协作和安全智能的解决方案,帮助组织加强应用程序安全和风险管理。
Rational AppScan Enterprise 将先进的应用程序安全测试与整个应用程序生命周期中的治理、协作和安全性智能相结合。它使企业能够降低应用程序风险,控制应用程序项目成本,以及遵守法规需求
- 集中控制企业级应用程序安全程序,在现有开发流程中推广安全测试实践
- 提供对应用程序安全和法规合规性风险的企业级可视性
- 集成整个软件开发生命周期内的安全测试,降低风险并减少修复成本
- 促进开发、测试和安全团队之间的协作
了解更多信息
购买 Rational AppScan Enterprise Edition
第一年的产品价格中包含 IBM 软件升级和支持。
购买后在线下载软件,无运输成本。
China 目前不提供在线购买功能。如有需求意向请通过如下方式联系 IBM 销售代表:
联系 IBM
- 产品询价
- E-mail 给我们
- 或即刻致电: 8008101818 转 5156(免费)
优先级代码: 100KT05W
Features and benefits
For years organizations have depended on Web-based software to run their business processes, conduct transactions and deliver increasingly sophisticated services to customers. Unfortunately, in the race to meet deadlines and stay ahead of the competition, many businesses fail to perform adequate security testing or take the time to make sure applications are in compliance with industry and regulatory standards. The result is that many companies may unknowingly expose corporate or personal data to cybercriminals who can exploit these vulnerabilities for fun and profit—placing the entire business at risk. And since many regulatory requirements mandate a degree of application security, these organizations also run the risk of failing to meet compliance audit requirements, which can result in fines and loss of customers. AppScan Enterprise enables organizations to take a strategic approach for addressing Web application security.
Key features:
Scalable, enterprise architecture that enables scanning of multiple applications simultaneously
Correlation of results discovered using dynamic and static analysis techniques
Ability to scans Web sites for both embedded malware and links to malicious or undesirable sites to ensure your Web site is not infecting visitors or directing them to unwanted or dangerous sites without their knowledge
Ability to test Web services
Advisories, fix recommendations and built-in training videos to facilitate the process of remediation once security vulnerabilities have been identified and validated
Issue management capabilities and integration with Defect Tracking Systems
Enterprise level reporting which provides visibility of the security and compliance risk the identified security issues present
Performance metrics and trending that give Management a sense of the progress being made
Flexible detailed security issues reports that enable users to group and organize their report data in multiple ways
Over 40 out-of-the box security compliance reports including PCI Data Security Standard, Payment Application Data Security (PA-DSS) (new), ISO 27001 and ISO 27002 , HIPAA, GLBA and Basel II
Role-based reporting access and scan permissions to help enforce test polices and provide governance
| Operating System | Software | Hardware |
|---|---|---|
Note: 1. For best results, install all critical Microsoft updates. 2. If the website being scanned uses technologies such as Flash, Windows Media, and additional character sets, these technologies must also be installed on the agent server machines. Supported Integrations
|
Database
Web Server
Other prerequisites
Supported Browsers
|
Processor
Memory
Hard disk
|
-
应用安全
- Lotus Protector for Mail Security
- Rational AppScan Build Edition
- Rational AppScan Enterprise Edition
- Rational AppScan Express Edition
- Rational AppScan OnDemand
- Rational AppScan OnDemand Production Site Monitoring
- Rational AppScan Reporting Console
- Rational AppScan Standard Edition
- Rational AppScan Tester Edition
- Rational AppScan Source Edition
- Rational Virtual Forge CodeProfiler for AppScan Source Edition
- Tivoli Identity and Access Manager