CWE
CWE/SANS Top 25 Most Dangerous Software Errors Common Weakness Scoring System
Common Weakness Risk Analysis Framework
Home > Compatibility > Declarations to Be CWE-Compatible  

Declarations to Be CWE-Compatible
Declarations to Be CWE-Compatible

TOTALS
Organizations with Declarations: 28
Products & Services with Declarations: 46

The organizations listed below have declared their intent to make their information security product or services CWE-compatible.

You may also Make a Declaration for your product or service.


A product or service may be CWE-compatible with one or more of the following:


Declarations

Products are listed alphabetically by organization name under each status level: Available or Planned.

Available Status

Product (33) Organization (21) Type Country (8) Capability Status
Architectural and Design Risk Management Cigital, Inc. Software Security Architecture and Design Risk Assessment and Management United States Output

Searchable

Coverage

Available

Available

Planned

CAST Application Intelligence Platform CAST Automated Application Assessment Platform France Output

Searchable

Coverage

Available

Available

Available

Cenzic Hailstorm Professional Cenzic, Inc. Web Application Penetration Testing and Vulnerability Management System United States Output

Searchable

Coverage

Available

Available

Available

Cenzic Hailstrom Enterprise ARC Cenzic, Inc. Web Application Security Risk Management Platform United States Output

Searchable

Coverage

Available

Available

Available

Certification of Software Lifecycle Personnel ISC2 The International Information Systems Security Certification Consortium Professional Certification United States Output

Searchable

Coverage

Available

Planned

Planned

CodeSecure Enterprise Armorize Technologies, Inc. Web Application Source Code Analysis Tool United States Output

Searchable

Coverage

Available

Available

Available

CodeSecure Verifier Armorize Technologies, Inc. Web Application Source Code Analysis Suite United States Output

Searchable

Coverage

Available

Available

Available

CodeSecure Workbench Armorize Technologies, Inc. Web Application Source Code Analysis Tool United States Output

Searchable

Coverage

Available

Available

Available

COREvidence NETpeas, SA Cloud-Based, Multi-Engines Vulnerability Management Service France Output

Coverage

Searchable

Available

Available

Planned

Coverity Integrity Center Coverity, Inc. Static Analysis Tool United States Output

Searchable

Coverage

Available

Available

Available

Coverity Prevent Coverity, Inc. Static Analysis Tool United States Output

Searchable

Coverage

Available

Available

Available

CxSuite Checkmarx Static Application Security Testing/Application Security Code Review Israel Output

Searchable

Coverage

Available

Planned

Planned

DEFENSICS X Codenomicon Ltd. Fuzz Testing Tool with Integrated Capability to Report CWE Identifiers and Descriptions for Found Vulnerabilities Finland Output

Searchable

Coverage

Available

Available

Planned

EMC Product Security Policy (PSP) EMC Corporation and RSA (The Security Division of EMC) Enterprise Policy for Secure Product Development United States Output

Searchable

Available

Available

EMC Security Development Lifecycle (SDL) EMC Corporation and RSA (The Security Division of EMC) Enterprise Secure Development Lifecycle United States Output

Searchable

Available

Available

EMC Vulnerability Response Policy (VRP) EMC Corporation and RSA (The Security Division of EMC) Enterprise Response Policy for Product Vulnerabilities United States Output

Searchable

Available

Available

Jtest Parasoft Corporation Java Software Quality Analysis and Testing Solution United States Output

Searchable

Coverage

Available

Available

Planned

JVN iPedia Information-Technology Promotion Agency (IPA), Japan Vulnerability Countermeasure Information Database Japan Output

Searchable

Coverage

Available

Available

Available

LDRA Testbed LDRA Static and Dynamic Software Analysis Tool Suite United Kingdom Output

Searchable

Coverage

Available

Available

Planned

MyJVN Information-Technology Promotion Agency (IPA), Japan Filtered Vulnerability Countermeasure Information Tool Japan Output

Searchable

Coverage

Available

Available

Available

Rational AppScan Standard Edition IBM Rational Web Application Security Assessment Tool United States Output

Searchable

Coverage

Available

Available

Available

Secure Code Review Astyran Pte Ltd. Secure Code Review Singapore Output

Searchable

Coverage

Available

Available

Planned

Secure Code Review with Automated Tools Cigital, Inc. Security Code Assessment United States Output

Searchable

Coverage

Available

Available

Planned

Secure Design Review Astyran Pte Ltd. Secure Design Review Singapore Output

Searchable

Coverage

Available

Available

Planned

Secure Development Lifecycle Apple Secure Development Lifecycle United States Output

Coverage

Available

Available

Secure programming class, CS390S CERIAS/Purdue University Secure Programming Class and Publicly Available Teaching Materials United States Output

Searchable

Coverage

Available

Available

Planned

Security Training and Awareness (various courses) Cigital, Inc. Software Security Training and Awareness Courses United States Output

Searchable

Coverage

Available

Available

Planned

SecurityAlert SecurityReason Web Application Security Risk Management Platform Poland Output

Searchable

Coverage

Available

Available

Available

SofCheck Inspector for Ada SofCheck Inc. Static Analysis and Fault Detection Tool United States Searchable

Output

Coverage

Available

Planned

Planned

Software Assurance Assessment KDM Analytics Software Assurance Assessment Service United States Output

Searchable

Coverage

Available

Available

Planned

Symantec Product Security Symantec Symmunize (Symantec's Secure Development Lifecycle Process) United States Output

Searchable

Available

Available

TBvision LDRA Static and Dynamic Software Analysis Tool Suite United Kingdom Output

Searchable

Coverage

Available

Available

Planned

Web Application Vulnerability Assessment Astyran Pte Ltd. Application Vulnerability Assessment Singapore Output

Searchable

Coverage

Available

Available

Available

Planned Status

Product (13) Organization (8) Type Country (1) Capability Status
EC-Council Certified Secure Programmer EC-Council Secure Programmer Certification Program United States Output

Searchable

Planned

Planned

HP DevInspect Hewlett-Packard Web Application Security Assessment Tool for Developers United States Output

Searchable

Coverage

Planned

Planned

Planned

HP QAInspect Hewlett-Packard Web Application Security Assessment Tool for QA United States Output

Searchable

Coverage

Planned

Planned

Planned

HP SaaS for ASC Hewlett-Packard Web Application Security Assessment and AMP delivered through Software-as-a-Service United States Output

Searchable

Coverage

Planned

Planned

Planned

QA*C - CWE Compliance Module for C Programming Language Programming Research, Inc. Source Code Static Analysis Product Suite United States Output

Searchable

Coverage

Planned

Planned

Planned

QA*CPP - CWE Compliance Module for C++ Programming Language Programming Research, Inc. Source Code Static Analysis Product Suite United States Output

Searchable

Coverage

Planned

Planned

Planned

Rational AppScan Enterprise Edition IBM Rational Enterprise Web Application Security Assessment Tool United States Output

Searchable

Coverage

Planned

Planned

Planned

Rational AppScan Source Edition IBM Rational Source Code Testing Tool United States Output

Searchable

Coverage

Planned

Planned

Planned

Rational AppScan Tester Edition IBM Rational Development-Time Web Application Security Testing Tool United States Output

Searchable

Coverage

Planned

Planned

Planned

Red Hat Customer Portal Red Hat, Inc. Customer Assessment Service United States Output

Searchable

Coverage

Planned

Planned

Planned

Secure Application Development Training Courses SkillBridge, LLC Instructor Led Training United States Output

Searchable

Coverage

Planned

Planned

Planned

Secure Programming Exams/Assessments SANS Institute Professional Secure Programming Examination United States Output

Searchable

Coverage

Planned

Planned

Planned

WebLayers Center Security Policy Library WebLayers, Inc. Software Development Lifecycle (SDLC) Governance United States Output

Searchable

Coverage

Planned

Planned

Planned

Page Last Updated: May 03, 2012