Enhancements to CA Veracode Verified Program Validate Secure Coding for DevOps and Agile Processes
March 19, 2018

Veracode, acquired by CA Technologies, announced the evolution of CA Veracode Verified, a program that provides third-party validation of a company’s secure software developing processes.

With approximately 30 percent of all breaches occurring as a result of a vulnerability at the application layer, software purchasers are demanding more insight into the security of the software they are buying. CA Veracode Verified empowers software vendors to demonstrate their commitment to creating secure software.

The CA Veracode Verified program provides several benefits to companies participating in the program, including:

• A roadmap for adopting and maturing an application security program tied to practical outcomes and business value for the Modern Software Factory.

• Third-party attestation from an industry leader that an application has undergone security testing as part of the development process. This can help streamline the sales process to proactively address security concerns.

• A focus on the secure coding process, not just a point-in-time release, to embrace DevSecOps and the rapid delivery pace of DevOps and Agile development methods.

• A means of ensuring that third party software purchased or used meets a high standard of application security, to reduce enterprise risk.

“As software becomes a bigger component of value in all industries, every company is driven to become a modern software factory. Security becomes a competitive advantage as companies learn to create and buy high-quality, secure software. Too often we’re seeing security sacrificed to accommodate the speed of business,” said Chris Wysopal, CTO, CA Veracode. “The result is insecure software that causes extraordinarily damaging breaches. The CA Veracode Verified program provides both a roadmap towards secure software development and a quick means of determining the commitment to security made by potential software vendor. The program seal highlights organizations that make secure software development a competitive advantage by showing that they adopted a mature application security program that covers the entire SDLC.”

Successful application security is more than just scanning and fixing security flaws, it’s about a change in processes and procedures to embed security into the entire development process. CA Veracode Verified focuses on implementation of secure coding practices, not just recording point-in-time scans, which makes it ideal for today’s DevOps and Agile methods, where releases happen at very high frequency and security must be fully integrated throughout the lifecycle.

The CA Veracode Verified program recognizes three levels of maturity to help organizations and consumers understand the security posture of the software they purchase and use. The maturity levels are based on more than 12 years of software security trend data pulled from the CA Veracode Platform. This data provides best practices to help create a secure development process that minimizes vulnerabilities and reduces the risk of a breach.

Share this

Industry News

September 27, 2022

DevOps Institute will host SKILup Festival in Singapore on November 15, 2022.

September 27, 2022

Delinea announced the latest release of DevOps Secrets Vault, its high-speed vault for DevOps and DevSecOps teams.

September 27, 2022

The Apptainer community announced version 1.1.0 of the popular container system for secure, high-performance computing (HPC). Improvements in the new version provide a smaller attack surface for production deployments while offering features that improve and simplify the user experience.

September 26, 2022

Secure Code Warrior unveiled Coding Labs, a new mechanism that allows developers to more easily move from learning to applying secure coding knowledge, leading to fewer vulnerabilities in code.

September 26, 2022

ActiveState announced the availability of the ActiveState Artifact Repository.

September 26, 2022

Split Software announced the availability of its Feature Data Platform in the Microsoft Azure Marketplace.

September 22, 2022

Katalon announced the launch of the Katalon Platform, a modern and comprehensive software quality management platform that enables teams of any size to easily and efficiently test, launch, and optimize apps, products, and software.

September 22, 2022

StackHawk announced its Deeper API Security Test Coverage release.

September 21, 2022

Platform9 announced the launch of its latest open source project, Arlon.

September 21, 2022

Redpanda Data announced Redpanda Console.

September 21, 2022

mabl announced its availability as a private listing on Google Cloud Marketplace.

September 21, 2022

Zesty announced a $75 million Series B funding round led by B Capital and Series A investor Sapphire Ventures.

September 20, 2022

Opsera, the Continuous Orchestration platform for DevOps, announced a free trial of its no-code Salesforce Release Management platform for fast and secure Salesforce releases.

September 20, 2022

Sysdig announced ToDo and Remediation Guru.

September 20, 2022

AutoRABIT announced CodeScan Shield.