CWE
Home > Compatibility > Sort By Category  

Sort By Category
Sort By Category

All organizations participating in the Compatibility Program are listed below.

Assessment and Remediation Tool

Product Organization Type Capability Status
CAST Application Intelligence Platform CAST Automated Application Assessment Platform CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Yes
Yes
Planned
Yes
Cenzic Hailstorm Professional Cenzic, Inc. Web Application Penetration Testing and Vulnerability Management System CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
Cenzic Hailstrom Enterprise ARC Cenzic, Inc. Web Application Security Risk Management Platform CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
CodeSecure Enterprise Armorize Technologies, Inc. Web Application Source Code Analysis Tool CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
CodeSecure Verifier Armorize Technologies, Inc. Web Application Source Code Analysis Suite CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
CodeSecure Workbench Armorize Technologies, Inc. Web Application Source Code Analysis Tool CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
CodeSonar GrammaTech, Inc. Static Analysis Tool CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
Coverity Integrity Center Coverity, Inc. Static Analysis Tool CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Planned
Planned
Planned
Planned
Coverity Prevent Coverity, Inc. Static Analysis Tool CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Planned
Planned
Planned
Planned
CxSuite Checkmarx Static Application Security Testing/Application Security Code Review CWE Output
CWE Searchable
CWE Coverage
Yes
Planned
Planned
DEFENSICS 3 Codenomicon Ltd. Fuzz Testing Tool with Integrated Capability to Report CWE Identifiers and Descriptions for Found Vulnerabilities CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Yes
Yes
Yes
Planned
Fortify Source Code Analysis (SCA) Fortify Software Source Code Analysis Tool CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
Jtest Parasoft Corporation Java Software Quality Analysis and Testing Solution CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Yes
Yes
Yes
Planned
Klocwork Enterprise Development Suite Klocwork, Inc. Assessment and Remediation Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
LDRA Testbed LDRA Static and Dynamic Software Analysis Tool Suite CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Planned
Planned
Planned
Planned
MyJVN Information-Technology Promotion Agency (IPA), Japan Filtered Vulnerability Countermeasure Information Tool CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
Ounce Ounce Labs Static Source Code Analysis Tool CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
Rational AppScan Build Edition IBM Rational Web Application Security Testing Tool For QA CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Rational AppScan Developer Edition IBM Rational Embedded Build-Time Web Application Security Testing Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Rational AppScan Enterprise Edition IBM Rational Enterprise Web Application Security Assessment Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Rational AppScan Express Edition IBM Rational Web Application Security Assessment Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Rational AppScan Standard Edition IBM Rational Web Application Security Assessment Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Rational AppScan Tester Edition IBM Rational Development-Time Web Application Security Testing Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
SofCheck Inspector for Ada SofCheck Inc. Static Analysis and Fault Detection Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Yes
Planned

Assessment Service

Product Organization Type Capability Status
Architectural and Design Risk Management Cigital, Inc. Software Security Architecture and Design Risk Assessment and Management CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Planned
HP SaaS for ASC HP Application Security Center Web Application Security Assessment and AMP delivered through Software-as-a-Service CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Secure Code Review with Automated Tools Cigital, Inc. Security Code Assessment CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Planned
Secure Programming Exams/Assessments SANS Institute Professional Secure Programming Examination CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Security-Database Web Services Security-Database Web Services CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
SecurityReview Veracode, Inc. Assessment Service CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
Software Assurance Assessment KDM Analytics Software Assurance Assessment Service CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Yes
Yes
Yes
Planned

Database/Knowledge Repository

Product Organization Type Capability Status
JVN iPedia Information-Technology Promotion Agency (IPA), Japan Vulnerability Countermeasure Information Database CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
LDRA Testbed LDRA Static and Dynamic Software Analysis Tool Suite CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Planned
Planned
Planned
Planned
Security-Database Web Services Security-Database Web Services CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
SecurityAlert SecurityReason Web Application Security Risk Management Platform CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Yes
SofCheck Inspector for Ada SofCheck Inc. Static Analysis and Fault Detection Tool CWE Output
CWE Searchable
CWE Coverage
Planned
Yes
Planned

Education Offering

Product Organization Type Capability Status
Certification of Software Lifecycle Personnel ISC2 The International Information Systems Security Certification Consortium Vulnerability Countermeasure Information Database CWE Output
CWE Searchable
CWE Coverage
Yes
Planned
Planned
Secure Application Development Training Courses SkillBridge, LLC Instructor Led Training CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Secure programming class, CS390S CERIAS/Purdue University Secure Programming Class and Publicly Available Teaching Materials CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Planned
Secure Programming Exams/Assessments SANS Institute Professional Secure Programming Examination CWE Output
CWE Searchable
CWE Coverage
Planned
Planned
Planned
Security Training and Awareness (various courses) Cigital, Inc. Software Security Training and Awareness Courses CWE Output
CWE Searchable
CWE Coverage
Yes
Yes
Planned

Software Development Practices

Product Organization Type Capability Status
Certification of Software Lifecycle Personnel ISC2 The International Information Systems Security Certification Consortium Vulnerability Countermeasure Information Database CWE Output
CWE Searchable
CWE Coverage
Yes
Planned
Planned
EMC Product Security Policy (PSP) EMC Corporation and RSA (The Security Division of EMC) Enterprise Policy for Secure Product Development CWE Output
CWE Searchable
CWE Coverage
CWE Documentation
Yes
Yes
No
Yes
EMC Security Development Lifecycle (SDL) EMC Corporation and RSA (The Security Division of EMC) Enterprise Secure Development Lifecycle CWE Output
CWE Searchable
CWE Coverage
CWE Documentation
Yes
Yes
No
Yes
EMC Vulnerability Response Policy (VRP) EMC Corporation and RSA (The Security Division of EMC) Enterprise Response Policy for Product Vulnerabilities CWE Output
CWE Searchable
CWE Coverage
CWE Documentation
Yes
Yes
No
Yes
Secure Development Lifecycle Apple Secure Development Lifecycle CWE Output
CWE Searchable
CWE Documentation
CWE Coverage
Yes
No
No
Yes
Page Last Updated: October 05, 2009