HCL AppScan Benefits
TH
TimHill
Director For Security Products at a manufacturing company with 10,001+ employees
It has certainly helped us find vulnerabilities in our software, so this is priceless in the end.
IBM Application Security has contributed to the maturity of our AppScan risk management program.
While it depends on the product, on average ten percent of our code is open source. Many products are either zero percent open source or maybe up to ten percent. They could possible be up to twenty percent open source, but never more than that.
It helps the organization the way we process the entire thing. It has actually helped a little bit with the speed of delivery too, which was surprising because most people thought it would be the other way around.
IBM Applications Security has contributed to the maturity of our AppSec risk management program. We've been working on our risk management program overall, for security development, and this has been a great asset to have.
We also use the solution to security test open-source applications. I'd say better than 70-75% of our applications are open-source. To me, a lot of people overly focus on open-source. That's because they believe that all the closed-source or proprietary is, in fact, secure. That's not necessarily the case. The issue is, when you take code and you're combining these different proprietary and open-source, packages, you have to test them all in the context where you're using them. And therein is the real issue. To me, it's not so much about the open-source, it's about all code. I believe all code has something that I have to look at.
We have a number of projects running concurrently, so I look at the aggregate. I try not to go to what's done on a single product. However, having said that, since we had nothing in dynamic and now we do, that's a huge improvement. You might say then that it was 100% improvement. I don't know if I would give it quite that number, but it is a huge improvement. It's quite near that number.
EO
SeniorSe47a0
Senior Security Specialist at a transportation company with 10,001+ employees
It has contributed to the maturity of our AppSec risk management program. I would rate that maturity level as eight out of 10. The testing part of your application's security is very valuable. You can't avoid that.
Applications are the faces of companies to the world. How much your application is secure equals how much your brand is secure. AppScan is a very major part of of the story.
We don't use it to test open-source code.
Buyer's Guide
HCL AppScan
March 2024
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,415 professionals have used our research since 2012.
Usually when we deploy the application, there is a process for ethical hacking. The main benefit is that, the ethical hacking is almost clean, every time. So it's less cost, less effort, less time to production.
AppScan has absolutely contributed to the maturity of our AppSec risk management. I would rate that maturity at only nine out of 10 because there are things that we could be doing better. Not only because of our internal processes, but because we need to adopt to the clients' processes, and that adopting always has small gaps. But generally, it's pretty awesome.
We don't use it to security test open-source applications but we do use it for open-source models, or libraries.
View full review »Before we had this solution, our security team was doing manual reviews with the scripts. This would take us a lot of work hours and a lot of people were involved in the process.
Now we just send it to AppScan and we can do other stuff like defining processes or dealing with management issues. We can focus on other aspects of our security.
It helps us avoid any downtime in the applications when they are already in production. It also prevents any vulnerability or security breaches.
View full review »Security issues reported by the tool help customers write secure code.
View full review »TD
reviewer1415661
General Manager at a consultancy with 51-200 employees
It takes care of our dynamic scanning needs.
View full review »I'm mainly working on the licensing side and not the technical side, so I don't get this kind of feedback.
View full review »It decreases the operational risk, security risk, a lot. In fact, when we first used it, the number of vulnerability alerts generated by the tool was huge. As time goes on, we can decrease those vulnerabilities because we learn from it. So, in the next release of the software, or new software that we have to develop, we know upfront that we should take care of some of the characteristics of the software.
View full review »PN
Prasoon Nigam
Security Consultant at a consultancy with 10,001+ employees
IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability.
View full review »MH
SeniorCl3552
Senior Cloud Architect at a tech company with 1,001-5,000 employees
It provides a better integration for our ecosystem. From a Fortinet perspective, this can lead to integration of selling our own products.
View full review »With AppScan, we are now deploying less defects to production.
View full review »SC
Sungmin Chun
Chief researcher at INSEC Security
- We were able to easily diagnose a large number of web applications automatically.
- The depth was low, but the part that the user could miss was also diagnosed.
JS
Shaikh Jamal Uddin
Cybersecurity Architecture and Technology Lead at Appxone
This solution saves us time due to the low number of false positives detected. Other scanners have an issue with respect to reporting false positives.
View full review »The benefits are that we that we can find security vulnerabilities fast, get that back to development teams, and report on those. They can then act, fix the issues, and we'll have a secure code in place.
View full review »It has certainly improved our organization In terms of quality of solutions that are developed.
View full review »Buyer's Guide
HCL AppScan
March 2024
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,415 professionals have used our research since 2012.