Enhancements to CA Veracode Verified Program Validate Secure Coding for DevOps and Agile Processes
March 19, 2018

Veracode, acquired by CA Technologies, announced the evolution of CA Veracode Verified, a program that provides third-party validation of a company’s secure software developing processes.

With approximately 30 percent of all breaches occurring as a result of a vulnerability at the application layer, software purchasers are demanding more insight into the security of the software they are buying. CA Veracode Verified empowers software vendors to demonstrate their commitment to creating secure software.

The CA Veracode Verified program provides several benefits to companies participating in the program, including:

• A roadmap for adopting and maturing an application security program tied to practical outcomes and business value for the Modern Software Factory.

• Third-party attestation from an industry leader that an application has undergone security testing as part of the development process. This can help streamline the sales process to proactively address security concerns.

• A focus on the secure coding process, not just a point-in-time release, to embrace DevSecOps and the rapid delivery pace of DevOps and Agile development methods.

• A means of ensuring that third party software purchased or used meets a high standard of application security, to reduce enterprise risk.

“As software becomes a bigger component of value in all industries, every company is driven to become a modern software factory. Security becomes a competitive advantage as companies learn to create and buy high-quality, secure software. Too often we’re seeing security sacrificed to accommodate the speed of business,” said Chris Wysopal, CTO, CA Veracode. “The result is insecure software that causes extraordinarily damaging breaches. The CA Veracode Verified program provides both a roadmap towards secure software development and a quick means of determining the commitment to security made by potential software vendor. The program seal highlights organizations that make secure software development a competitive advantage by showing that they adopted a mature application security program that covers the entire SDLC.”

Successful application security is more than just scanning and fixing security flaws, it’s about a change in processes and procedures to embed security into the entire development process. CA Veracode Verified focuses on implementation of secure coding practices, not just recording point-in-time scans, which makes it ideal for today’s DevOps and Agile methods, where releases happen at very high frequency and security must be fully integrated throughout the lifecycle.

The CA Veracode Verified program recognizes three levels of maturity to help organizations and consumers understand the security posture of the software they purchase and use. The maturity levels are based on more than 12 years of software security trend data pulled from the CA Veracode Platform. This data provides best practices to help create a secure development process that minimizes vulnerabilities and reduces the risk of a breach.

Share this

Industry News

November 21, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux 9.5, the latest version of the enterprise Linux platform.

November 21, 2024

Securiti announced a new solution - Security for AI Copilots in SaaS apps.

November 20, 2024

Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.

November 20, 2024

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:

November 20, 2024

Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.

November 20, 2024

Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.

November 19, 2024

OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.

November 19, 2024

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.

November 19, 2024

Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.

November 19, 2024

Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.

November 19, 2024

Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.

November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

November 19, 2024

Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.