|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| TOTALS | |
| Organizations with Declarations: 30 | |
| Products & Services with Declarations: 48 | |
The organizations listed below have declared their intent to make their information security product or services CWE-compatible.
You may also Make a Declaration for your product or service.
A product or service may be CWE-compatible with one or more of the following:
Products are listed alphabetically by organization name under each status level: Available or Planned.
| Product (39) | Organization (24) | Type | Country (10) | Capability | Status |
|---|---|---|---|---|---|
| Architectural and Design Risk Management | Cigital, Inc. | Software Security Architecture and Design Risk Assessment and Management | United States |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| CAST Application Intelligence Platform | CAST | Automated Application Assessment Platform | France |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Cenzic Hailstorm Enterprise ARC | Cenzic, Inc. | Application Security Assessment Tool | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Cenzic Hailstorm Professional | Cenzic, Inc. | Application Security Assessment Tool | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Certification of Software Lifecycle Personnel | ISC2 The International Information Systems Security Certification Consortium | Professional Certification | United States |
Output
Searchable
Coverage
|
Available
Planned
Planned
|
| cIFrex | CXSecurity | Free Security Research Tool | Poland |
Output
Searchable
Documentation
Coverage
|
Available
Available
Available
Available
|
| CodeSecure Enterprise | Armorize Technologies, Inc. | Web Application Source Code Analysis Tool | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| CodeSecure Verifier | Armorize Technologies, Inc. | Web Application Source Code Analysis Suite | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| CodeSecure Workbench | Armorize Technologies, Inc. | Web Application Source Code Analysis Tool | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Conviso Security Compliance (CSC) | Conviso Application Security | Vulnerability Identification and Management | Brazil |
Output
Searchable
Coverage
|
Available
Available
Available
|
| COREvidence | NETpeas, SA | Cloud-Based, Multi-Engines Vulnerability Management Service | France |
Output
Coverage
Searchable
|
Available
Available
Planned
|
| CxCloud | Checkmarx | Static Code Analysis On Demand | Israel |
Output
Searchable
Coverage
|
Available
Available
Available
|
| CxEnteprise | Checkmarx | Static Code Analysis On Premise | Israel |
Output
Searchable
Coverage
|
Available
Available
Available
|
| CxSuite | Checkmarx | Static Application Security Testing/Application Security Code Review | Israel |
Output
Searchable
Coverage
|
Available
Available
Available
|
| DEFENSICS X | Codenomicon Ltd. | Fuzz Testing Tool with Integrated Capability to Report CWE Identifiers and Descriptions for Found Vulnerabilities | Finland |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| EMC Product Security Policy (PSP) | EMC Corporation and RSA (The Security Division of EMC) | Enterprise Policy for Secure Product Development | United States |
Output
Searchable
Coverage
|
Available
Available
No
|
| EMC Security Development Lifecycle (SDL) | EMC Corporation and RSA (The Security Division of EMC) | Enterprise Secure Development Lifecycle | United States |
Output
Searchable
Coverage
|
Available
Available
No
|
| EMC Vulnerability Response Policy (VRP) | EMC Corporation and RSA (The Security Division of EMC) | Enterprise Response Policy for Product Vulnerabilities | United States |
Output
Searchable
Coverage
|
Available
Available
No
|
| IBM Security AppScan Enterprise | IBM Security Systems | Enterprise Web Application Security Assessment Tool | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| IBM Security AppScan Source | IBM Security Systems | Source Code Testing Tool | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Jtest | Parasoft Corporation | Java Software Quality Analysis and Testing Solution | United States |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| JVN iPedia | Information-technology Promotion Agency, Japan (IPA) | Vulnerability Countermeasure Information Database | Japan |
Output
Searchable
Coverage
|
Available
Available
Available
|
| LDRA Testbed | LDRA | Static and Dynamic Software Analysis Tool Suite | United Kingdom |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| MyJVN | Information-technology Promotion Agency, Japan (IPA) | Filtered Vulnerability Countermeasure Information Tool | Japan |
Output
Searchable
Coverage
|
Available
Available
Available
|
| SDElements | SD Elements | Secure Application Lifecycle Management (SALM) Tool | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Secure Code Review | Astyran Pte Ltd. | Secure Code Review | Singapore |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| Secure Code Review with Automated Tools | Cigital, Inc. | Security Code Assessment | United States |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| Secure Design Review | Astyran Pte Ltd. | Secure Design Review | Singapore |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| Secure Development Lifecycle | Apple Computer, Inc. | Secure Development Lifecycle | United States |
Output
Coverage
Searchable
|
Available
Available
No
|
| Secure programming class, CS390S | CERIAS/Purdue University | Secure Programming Class and Publicly Available Teaching Materials | United States |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| Security Training and Awareness (various courses) | Cigital, Inc. | Software Security Training and Awareness Courses | United States |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| SecurityAlert | SecurityReason | Security Advisories, Database, and Archive | Poland |
Output
Searchable
Coverage
|
Available
Available
Available
|
| SofCheck Inspector for Ada | SofCheck Inc. | Static Analysis and Fault Detection Tool | United States |
Searchable
Output
Coverage
|
Available
Planned
Planned
|
| Software Assurance Assessment | KDM Analytics | Software Assurance Assessment Service | United States |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| SPARROW | Fasoo.com, Inc. | Semantic-Based Static Program Analysis Engine | Korea |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| Symantec Product Security | Symantec Corporation | Symmunize (Symantec's Secure Development Lifecycle Process) | United States |
Output
Searchable
Coverage
|
Available
Available
No
|
| TBvision | LDRA | Static and Dynamic Software Analysis Tool Suite | United Kingdom |
Output
Searchable
Coverage
|
Available
Available
Planned
|
| Tool Output Integration Framework (TOIF) | KDM Analytics | Open Source Vulnerability Detection Platform | United States |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Web Application Vulnerability Assessment | Astyran Pte Ltd. | Application Vulnerability Assessment | Singapore |
Output
Searchable
Coverage
|
Available
Available
Available
|
| Product (9) | Organization (6) | Type | Country (1) | Capability | Status |
|---|---|---|---|---|---|
| EC-Council Certified Secure Programmer | EC-Council | Secure Programmer Certification Program | United States |
Output
Searchable
Coverage
|
Planned
Planned
No
|
| HP DevInspect | Hewlett-Packard | Web Application Security Assessment Tool for Developers | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| HP QAInspect | Hewlett-Packard | Web Application Security Assessment Tool for QA | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| HP SaaS for ASC | Hewlett-Packard | Web Application Security Assessment and AMP delivered through Software-as-a-Service | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| QA*C - CWE Compliance Module for C Programming Language | Programming Research, Inc. | Source Code Static Analysis Product Suite | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| QA*CPP - CWE Compliance Module for C++ Programming Language | Programming Research, Inc. | Source Code Static Analysis Product Suite | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| Rational AppScan Tester Edition | IBM Rational | Development-Time Web Application Security Testing Tool | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| Secure Application Development Training Courses | SkillBridge, LLC | Instructor Led Training | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
| Secure Programming Exams/Assessments | SANS Institute | Professional Secure Programming Examination | United States |
Output
Searchable
Coverage
|
Planned
Planned
Planned
|
|
|
|||