Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
By Arthur Hicken - CodeCurmudgeon
Contributor profile | More stories
Story Views
Now:
Last hour:
Last 24 hours:
Total:

SCA is the Latest AppSec Silver Bullet

% of readers think this story is Fact. Add your two cents.


The realm of application security and cybersecurity is littered with promised silver bullets. New technologies come along and promise to solve all your old security problems and world hunger as an extra bonus. Too often these technologies actual value remains obscured by snake-oil marketing making bold promises as a way to gain market share.

Those who’ve followed me for any period of time know my low tolerance for snake-oil claims. Things like metrics that will point to all your bugs, or static analysis that will eliminate all bugs or allow you to prove that your application is bug free at a few that persist in software development.

These simple solutions find an audience because security is a difficult tedious problem that requires mature thought-out processes and actions. Most security incidents occur not because a super villain targeted an organization with a complex campaign, but because the organization failed to follow best practices like keeping patches up-to-date, having rational password policies (8 characters in this day and age? Really?) and doing secure software engineering like static code analysis or SAST. It’s much easier to hope that you can buy a tool and it’ll just do the job for you. But it won’t. That tool doesn’t exist. For the last decade we’ve had failed SAST organizations buying and building other technologies that properly complement SAST but they’re selling them as a replace because they failed in their SAST business.

Don’t misunderstand me – SCA is just the latest tool in your cybersecurity toolbox. It’s an important addition to what you’re doing and was definitely missing in a world where everyone is using some amount of OSS components. However I fear that its real value will be destroyed by the marketing hype as vendors who are snapping up SCA tools try to sell it as the total final solution to software security problems.

Yes, SCA is important. You should do it. If you’re not doing it, you’re missing the boat. But don’t expect it to solve all your problems, or replace even a single one of the tools and processes in your secure software development lifecycle, because that’s not what it is for. It was created to fill a gap, not replace existing tools and processes. Simply put, software composition analysis finds open source packages in your application (some tools look for other than OSS, but most do not) and then checks for open issues in the form of CVEs against those projects. In other words, SCA looks for known problems like an anti-virus tool would. It doesn’t actually check the security of your application, just the patch level. (Note, some tools also do OSS license management. This is also an important issue, but it’s not a security issue, it’s a business problem.)

As always, beware someone with crazy promises of simple solutions to complex problems. For fun you might want to read my rant on this in SD times. No, this isn’t a rant, when I’m ranting you’ll know it.

Stay secure out there.

SCA is the Latest AppSec Silver Bullet originally appeared on Code Curmudgeon on August 15, 2019.

The post SCA is the Latest AppSec Silver Bullet appeared first on Code Curmudgeon.

http://codecurmudgeon.com/wp Twitter: @codecurmudgeon


Source: https://codecurmudgeon.com/wp/2019/08/sca-is-the-latest-appsec-silver-bullet/


Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Please Help Support BeforeitsNews by trying our Natural Health Products below!


Order by Phone at 888-809-8385 or online at https://mitocopper.com M - F 9am to 5pm EST

Order by Phone at 866-388-7003 or online at https://www.herbanomic.com M - F 9am to 5pm EST

Order by Phone at 866-388-7003 or online at https://www.herbanomics.com M - F 9am to 5pm EST


Humic & Fulvic Trace Minerals Complex - Nature's most important supplement! Vivid Dreams again!

HNEX HydroNano EXtracellular Water - Improve immune system health and reduce inflammation.

Ultimate Clinical Potency Curcumin - Natural pain relief, reduce inflammation and so much more.

MitoCopper - Bioavailable Copper destroys pathogens and gives you more energy. (See Blood Video)

Oxy Powder - Natural Colon Cleanser!  Cleans out toxic buildup with oxygen!

Nascent Iodine - Promotes detoxification, mental focus and thyroid health.

Smart Meter Cover -  Reduces Smart Meter radiation by 96%! (See Video).

Report abuse

    Comments

    Your Comments
    Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

    MOST RECENT
    Load more ...

    SignUp

    Login

    Newsletter

    Email this story
    Email this story

    If you really want to ban this commenter, please write down the reason:

    If you really want to disable all recommended stories, click on OK button. After that, you will be redirect to your options page.