Skip to main content

New IBM Security Scanning Software Protects Businesses From Hackers


ARMONK, NY - 13 Nov 2007: IBM (NYSE: IBM) today introduced new software to help customers protect their business from today's most advanced and complex web application security attacks. The first release of IBM Rational AppScan, a market leading web application security technology acquired by IBM from Watchfire in July 2007, is a key-part of IBM's software portfolio that helps ensures high quality applications are delivered to the marketplace.

Web applications are high value targets for hackers, yet many organizations have a difficult time tackling security due, in part, to a lack of application security knowledge and the size and complexity of today's websites that incorporate the latest in Web 2.0 technology. Businesses need automated solutions capable of identifying and protecting applications from these weaknesses. IBM Rational AppScan identifies, validates and reports on application security vulnerabilities and with this new version, introduces new features and reporting methods for security auditors while enabling a broader pool of IT roles to participate in and drive critical web application security testing.

Traditionally, testers, developers, and IT professionals have lacked the specific security knowledge needed to effectively run scans. New capabilities in IBM Rational AppScan, such as Scan Expert and State Inducer, broaden the availability of this critical function so IT personnel, software developers and testers are capable of running successful scans while at the same time also add new features to assist security professionals.

IBM Rational AppScan now includes educational material to help users build more secure applications. The product adds recorded web-based training (WBT) advisories that incorporate the industry's first application security training directly into the solution. WBT is an ideal way to educate non-security professionals on application security fundamentals and product best practices. With the rapid emergence of new compliance legislation, IBM Rational AppScan helps organizations comply with dozens of industry standards and has been updated to include a leading 44 out-of-the-box compliance reports including the Family Education Rights and Privacy Act (FERPA), and payment application best practices (PABP) as suggested by the credit card industry.

"With IBM Rational AppScan, Standard Chartered Bank is educating its developers and IT staff on the importance of web application security incorporated throughout the development lifecycle," said John Meakin, group head of information security, Standard Chartered Bank. "IBM Rational AppScan lets us establish best practice in our coding and testing processes, thereby ensuring the security and compliance of our web applications. This is reducing costs, enhancing the security of our products, and improving our security testing productivity."

Businesses today have hundreds of critical applications that need to be tested in a timely manner. Integrating security with quality management testing tools simplifies security testing and remediation throughout the software lifecycle. IBM has also introduced new enhancements to its IBM Rational software delivery portfolio to make it even easier for customers to deliver higher quality, scalable applications.

For example, telecommunications companies can now take advantage of IBM Rational Performance Tester's support for VoIP systems, internet telephony and instant messaging via SIP (session initiation protocol) -- a key standard in the telecommunications industry. New data-driven keyword testing capabilities in IBM Rational Manual testers now allows business users and manual testers to easily automate and reuse test assets without incurring excessive automation overhead and investment.

Best of breed security and quality testing solutions integrated from one vendor enables IBM customers to more effectively build security into their application delivery process.

"Traditionally, Web application security testing has been owned by security experts, but that is not enough to stay in synch with the requirements of processes within companies today," said Dr. Danny Sabbah, general manager, IBM Rational Software. "The addition of IBM Rational AppScan will help users save time and money by incorporating web application testing much earlier in the software lifecycle process."

Availability:
IBM Rational AppScan will be available on November 19, 2007. Customers in Japan can also download a new Japanese-language version of IBM Rational AppScan.

For more information, visit http://www.ibm.com/software/rational/ or to download an evaluation copy of IBM Rational AppScan, please visit https://www.watchfire.com/securearea/appscan.aspx.

Contact(s) information

Sue Ann Wright
Watchfire, an IBM Company
1-613-599-3888 ext. 4039
sueannw@ca.ibm.com

Related XML feeds
Topics XML feeds
Software
Information Management (DB2), Workplace, Portal & Collaboration Software (Lotus), Tivoli, Rational, WebSphere, Open standards, open source