|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TOTALS | |
| Organizations with Declarations: 28 | |
| Products & Services with Declarations: 46 | |
The organizations listed below have declared their intent to make their information security product or services CWE-compatible.
You may also Make a Declaration for your product or service.
A product or service may be CWE-compatible with one or more of the following:
Products are listed alphabetically by organization name under each status level: Available or Planned.
| Product (33) | Organization (21) | Type | Country (8) | Capability | Status |
|---|---|---|---|---|---|
| Architectural and Design Risk Management | Cigital, Inc. | Software Security Architecture and Design Risk Assessment and Management | United States | Output
Searchable Coverage |
Available
Available Planned |
| CAST Application Intelligence Platform | CAST | Automated Application Assessment Platform | France | Output
Searchable Coverage |
Available
Available Available |
| Cenzic Hailstorm Professional | Cenzic, Inc. | Web Application Penetration Testing and Vulnerability Management System | United States | Output
Searchable Coverage |
Available
Available Available |
| Cenzic Hailstrom Enterprise ARC | Cenzic, Inc. | Web Application Security Risk Management Platform | United States | Output
Searchable Coverage |
Available
Available Available |
| Certification of Software Lifecycle Personnel | ISC2 The International Information Systems Security Certification Consortium | Professional Certification | United States | Output
Searchable Coverage |
Available
Planned Planned |
| CodeSecure Enterprise | Armorize Technologies, Inc. | Web Application Source Code Analysis Tool | United States | Output
Searchable Coverage |
Available
Available Available |
| CodeSecure Verifier | Armorize Technologies, Inc. | Web Application Source Code Analysis Suite | United States | Output
Searchable Coverage |
Available
Available Available |
| CodeSecure Workbench | Armorize Technologies, Inc. | Web Application Source Code Analysis Tool | United States | Output
Searchable Coverage |
Available
Available Available |
| COREvidence | NETpeas, SA | Cloud-Based, Multi-Engines Vulnerability Management Service | France | Output
Coverage Searchable |
Available
Available Planned |
| Coverity Integrity Center | Coverity, Inc. | Static Analysis Tool | United States | Output
Searchable Coverage |
Available
Available Available |
| Coverity Prevent | Coverity, Inc. | Static Analysis Tool | United States | Output
Searchable Coverage |
Available
Available Available |
| CxSuite | Checkmarx | Static Application Security Testing/Application Security Code Review | Israel | Output
Searchable Coverage |
Available
Planned Planned |
| DEFENSICS X | Codenomicon Ltd. | Fuzz Testing Tool with Integrated Capability to Report CWE Identifiers and Descriptions for Found Vulnerabilities | Finland | Output
Searchable Coverage |
Available
Available Planned |
| EMC Product Security Policy (PSP) | EMC Corporation and RSA (The Security Division of EMC) | Enterprise Policy for Secure Product Development | United States | Output
Searchable |
Available
Available |
| EMC Security Development Lifecycle (SDL) | EMC Corporation and RSA (The Security Division of EMC) | Enterprise Secure Development Lifecycle | United States | Output
Searchable |
Available
Available |
| EMC Vulnerability Response Policy (VRP) | EMC Corporation and RSA (The Security Division of EMC) | Enterprise Response Policy for Product Vulnerabilities | United States | Output
Searchable |
Available
Available |
| Jtest | Parasoft Corporation | Java Software Quality Analysis and Testing Solution | United States | Output
Searchable Coverage |
Available
Available Planned |
| JVN iPedia | Information-Technology Promotion Agency (IPA), Japan | Vulnerability Countermeasure Information Database | Japan | Output
Searchable Coverage |
Available
Available Available |
| LDRA Testbed | LDRA | Static and Dynamic Software Analysis Tool Suite | United Kingdom | Output
Searchable Coverage |
Available
Available Planned |
| MyJVN | Information-Technology Promotion Agency (IPA), Japan | Filtered Vulnerability Countermeasure Information Tool | Japan | Output
Searchable Coverage |
Available
Available Available |
| Rational AppScan Standard Edition | IBM Rational | Web Application Security Assessment Tool | United States | Output
Searchable Coverage |
Available
Available Available |
| Secure Code Review | Astyran Pte Ltd. | Secure Code Review | Singapore | Output
Searchable Coverage |
Available
Available Planned |
| Secure Code Review with Automated Tools | Cigital, Inc. | Security Code Assessment | United States | Output
Searchable Coverage |
Available
Available Planned |
| Secure Design Review | Astyran Pte Ltd. | Secure Design Review | Singapore | Output
Searchable Coverage |
Available
Available Planned |
| Secure Development Lifecycle | Apple | Secure Development Lifecycle | United States | Output
Coverage |
Available
Available |
| Secure programming class, CS390S | CERIAS/Purdue University | Secure Programming Class and Publicly Available Teaching Materials | United States | Output
Searchable Coverage |
Available
Available Planned |
| Security Training and Awareness (various courses) | Cigital, Inc. | Software Security Training and Awareness Courses | United States | Output
Searchable Coverage |
Available
Available Planned |
| SecurityAlert | SecurityReason | Web Application Security Risk Management Platform | Poland | Output
Searchable Coverage |
Available
Available Available |
| SofCheck Inspector for Ada | SofCheck Inc. | Static Analysis and Fault Detection Tool | United States | Searchable
Output Coverage |
Available
Planned Planned |
| Software Assurance Assessment | KDM Analytics | Software Assurance Assessment Service | United States | Output
Searchable Coverage |
Available
Available Planned |
| Symantec Product Security | Symantec | Symmunize (Symantec's Secure Development Lifecycle Process) | United States | Output
Searchable |
Available
Available |
| TBvision | LDRA | Static and Dynamic Software Analysis Tool Suite | United Kingdom | Output
Searchable Coverage |
Available
Available Planned |
| Web Application Vulnerability Assessment | Astyran Pte Ltd. | Application Vulnerability Assessment | Singapore | Output
Searchable Coverage |
Available
Available Available |
| Product (13) | Organization (8) | Type | Country (1) | Capability | Status |
|---|---|---|---|---|---|
| EC-Council Certified Secure Programmer | EC-Council | Secure Programmer Certification Program | United States | Output
Searchable |
Planned
Planned |
| HP DevInspect | Hewlett-Packard | Web Application Security Assessment Tool for Developers | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| HP QAInspect | Hewlett-Packard | Web Application Security Assessment Tool for QA | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| HP SaaS for ASC | Hewlett-Packard | Web Application Security Assessment and AMP delivered through Software-as-a-Service | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| QA*C - CWE Compliance Module for C Programming Language | Programming Research, Inc. | Source Code Static Analysis Product Suite | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| QA*CPP - CWE Compliance Module for C++ Programming Language | Programming Research, Inc. | Source Code Static Analysis Product Suite | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| Rational AppScan Enterprise Edition | IBM Rational | Enterprise Web Application Security Assessment Tool | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| Rational AppScan Source Edition | IBM Rational | Source Code Testing Tool | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| Rational AppScan Tester Edition | IBM Rational | Development-Time Web Application Security Testing Tool | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| Red Hat Customer Portal | Red Hat, Inc. | Customer Assessment Service | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| Secure Application Development Training Courses | SkillBridge, LLC | Instructor Led Training | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| Secure Programming Exams/Assessments | SANS Institute | Professional Secure Programming Examination | United States | Output
Searchable Coverage |
Planned
Planned Planned |
| WebLayers Center Security Policy Library | WebLayers, Inc. | Software Development Lifecycle (SDLC) Governance | United States | Output
Searchable Coverage |
Planned
Planned Planned |
|
|
|||