SD Elements Scales Better than SAST and Delivers Benefits for High-Risk Applications

Security Compass
Security Compass
Published in
2 min readMay 28, 2019

Creating and implementing a secure application development process can be challenging. There are so many project-specific vulnerabilities and requirements that make it hard to cover everything at the outset. Many organizations try to identify security defects early on with code scanning (i.e., Static Analysis Security Testing or SAST). Their goal is to catch and fix security errors before releasing their software. However, one of the challenges that organizations experience is managing the results delivered by SAST/DAST tools. The often unreliable results produced by code scanners can limit organizations’ ability to scale their programs to a large number of applications.

Read the Scanner Gap Report

The Problem with Scanners

A major financial institution experienced this problem first-hand while onboarding applications into their SAST program. They found themselves struggling to manage a large number of scanner results. The scanners often missed critical issues and produced false alarms. Also, having limited availability of people with the necessary skills made it difficult to keep up with the amount of work. A single employee could only onboard 111 applications into the program per year, which meant that scaling the program would tie up valuable resources. In general, it was difficult for them to streamline and integrate their application security process with an agile development workflow.

Scaling Threat Modeling Activities is Hard

When this major financial institution began creating a threat modeling program, they wanted the activity to scale to a large number of applications, without all the overhead and unanticipated work that they experienced with their SAST program.

To onboard applications faster, the organization adopted and implemented SD Elements. This platform enabled automated threat modeling and built security requirements into their application security program. A single employee was able to onboard 240 applications in 4 months (while only spending half of their time on it). The initial run was so successful that they eventually onboarded 1500 high-risk applications and made it part of their standard development process. SD Elements scaled over 12x faster than their static analysis program.

Learn more about SD Elements

About Security Compass–

Security Compass is a leader in helping customers proactively manage cybersecurity risk, without slowing down business. Offering SD Elements, Just-in-Time Training, and Enterprise Delivery Services, as well as Verification Services, we help your organization efficiently deliver technology that’s secure by design. At the core of our solution is our policy-to-execution software platform, SD Elements, which translates policies into actionable tasks for technical teams. Security Compass services some of the world’s largest enterprises, as well as 4 of the largest tech companies in the world. We’re headquartered in Toronto with global offices in the United States and India. Follow Security Compass on Twitter @securitycompass or visit https://www.securitycompass.com/

--

--

Security Compass
Security Compass

We guide your team in building a customized security blueprint based on your SDLC and business needs to cost-effectively mitigate risks.