Fortify Flashcards
Give the elevator pitch for Fortify.
Fortify is a suite of tightly integrated solutions for identifying, prioritising, and helping with the process of fixing security vulnerabilities in software.
Give the elevator pitch for Fortify on Demand.
~ helps resolve software vulnerabilities using the only solution that fully integrates vulnerability analysis across the entire software lifecycle - from development to QA testing to deployed applications.
~ offers end-to-end application security, delivered as a service.
What are the 3 key value props of FoD?
#1 Secure Development: Finding and fixing application security issues early, during development, is far less costly than waiting until after an app has been deployed, so empowering developers to create secure software from inception is critical. #2 Security Testing: A dynamic or mobile assessment of the running app in a QA, test, staging or production environment simulates the real-world hacking techniques and attacks employed by the bad guys. #3 Production Monitoring: FoD provides all production application monitoring activities in a single, integrated place.
What are the personas to sell FoD to?
CISO, AppSec Manager, and QA
What is the CISO’s role in the FoD buying process and what are they responsible for?
Buyer/decision maker/budget owner. Responsible for protecting business and brand through overall risk management.
What is the AppSec Manager’s role in the FoD buying process and what are they responsible for?
Evaluator/project owner. Make sure all teams are aligned and manages AppSec program. Determines how to integrate in security testing and automate tool chains.
What is the QA’s role in the FoD buying process and what are they responsible for?
Influencer. Application testing/user.
What does the CISO care about reg. AppSec testing?
Securing intellectual property, sensitive data, and adhering to compliance.
What does the AppSec Manager care about reg. AppSec testing?
Ensuring apps are secure before releasing into production.
What does the QA care about reg. AppSec testing?
Tools ease of use and integration into the SDLC.
What topics to discuss with the CISO reg. using FoD for AppSec testing?
Fortify’s time to value/ROI
What topics to discuss with the AppSec Manager reg. using FoD for AppSec testing?
Testing speed, accuracy of results, line of code detail, remediation recommendations, ease of use, and integration capabilities.
What topics to discuss with the QA reg. using FoD for AppSec testing?
Line of code detail, remediation recommendations, and integration into developers native environment while meeting release deadlines.