Many of us in the development world rely on our code to be secure to ensure that our customers are safe while their web apps exist in the wild of the Internet. But sometimes, in order to save costs, we take potential shortcuts or put security to the end and rely on scanners to tell us our mistakes.
Security scanners are great but only when used properly with a company that truly assesses their own security. The other day a program that took many years to build and cost a company a large sum of cash was delivered for security purposes to a competitor security scanning company. Upon the completion of the scans, the scans were sent for Independent Verification and Validation (IV&V) separate from the security vendor and the company that produced the software.
It was at this IV&V that the issues became abundantly clear, did the IV&V personnel have the necessary skills for the IV&V?
The company that provided the product, or the customer, went through the findings results as well to show the IV& V team. The company indicated the entire finding list was, at its base level, majority false positives. This brings up two points to consider as a company and security vendor.
As to question 1, most security professionals do not have a large knowledge of coding. Couple that with the myriad of coding languages out there and you soon find, few people have all the needed skills.
As to question 2, In this case, with all the false positives, the security vendor should question this and determine if they chose the correct product from their “toolbox”.
The company in addition to stating it was almost all false positives, outsourced its responses to its development team who works overseas. This begs the question of whether the company itself knows how to read its own code.
Is the development team correct, only time will tell for this company and their future?
So how to eliminate these two points?
There are companies out there such as True-Positives that have personnel on staff who can assist with these 3 points plus they only require a small investment for big dividends on the end. The dividends are paid back to you as the customer in that world-class scanning software can be used at little to no money.
Talk to us today and get a free 1 on 1 AppSec consultation with one of our experts.