Harness®, the Modern Software Delivery Platform™ company, at the RSA Conference 2023, announced the latest release of its Security Testing Orchestration (STO) module, enabling developers to identify security issues earlier in the software development lifecycle and providing an innovative solution to ensure application software vulnerabilities are identified, deduped, prioritized, and remediated. With these new features, developers can work more efficiently and collaboratively with security practitioners to save their organization time, cost, effort, and reduce risk.
Announced in general availability last year, Harness STO empowers developers to integrate security throughout the software delivery process. This is a critical capability for companies seeking to avoid the potential financial, reputational, and legal costs of security vulnerabilities. This is an immediate need for organizations, as an Enterprise Strategy Group report found 35% of respondents reported releasing production-level code with known vulnerabilities and 45% released software without any testing and/or security checks. Harness STO lets developers prioritize application security vulnerability data, so they can deliver secure applications while maintaining deployment velocity.
Also Read: Trullion Raises Additional $15 Million to Expand AI-Powered Accounting Technology Portfolio
“For fast-moving organizations, efficiency and security are critical when it comes to software development and delivery, however, ensuring both can be challenging,” said Nick Durkin, Field CTO and VP, Field Engineering at Harness. “This suite of enhanced features in Harness STO empowers developers and security teams to work together, to increase both efficiency and productivity, simplify remediation, and offer greater governance and policy control, all while maintaining security controls.”
Key features of this latest STO release include:
- Remediation Recommendations: To improve efficiency, developers can triage and remediate security issues or vulnerabilities, without security expertise.
- Two-Step Exemption and Security Review: Improves collaboration between developers and security practitioners, provides enhanced vulnerability management, and a secure way to exclude vulnerabilities.
- Step Palette for Scanner Configuration: To save time, identify and resolve issues, developers can easily configure scanners with a list of menu options and customize configurations based on their needs. Provides provision to cache scanner images to improve scale and performance.
- Comparative Metrics as Output Variables: Provides visibility into new and fixed vulnerabilities in the pipeline, and enables developers to better automate and set customizable OPA policies, governance, and notifications.
SOURCE: PR Newswire