Checkmarx introduces Application Security Posture Management and Cloud Insights

Powerful new capabilities reduce “noise” by more than 80% with consolidation, correlation, prioritization and risk management that leverage visibility from code to cloud, incorporating runtime insights directly from cloud providers.

  • Wednesday, 12th June 2024 Posted 10 months ago in by Phil Alsop

Checkmarx has released Checkmarx Application Security Posture Management (ASPM) and Cloud Insights to provide organizations with unmatched visibility into their application security posture stretching from code to cloud. Available on the Checkmarx One AppSec platform, ASPM and Cloud Insights empower enterprises developing cloud-native applications to dramatically reduce application and business risk by delivering end-to-end insights into their application security posture, helping them better correlate, prioritize and triage remediation efforts.

 “Developers and AppSec teams are looking to consolidate the vulnerabilities and insights they get from security scanners and tools so they can identify and work on what are truly the most important to remediate in order to prevent issues in cloud runtime. With the increase in complexity inherent with cloud-native applications, and the various solutions required to detect vulnerabilities in every aspect of the applications, development and application security teams are simply lost,” said Kobi Tzruya, Chief Product Officer at Checkmarx. “Checkmarx Cloud Insights revolutionizes the way that teams approach application security by bringing runtime context back into the development life cycle, where Checkmarx helps them prioritize. Now developers can focus on what matters most, allowing them to make the most effective remediation efforts in less time.”

Checkmarx ASPM correlates and prioritizes security signals from every application security solution in the enterprise development environment, to improve visibility, reduce risk and better manage overall application security posture. ASPM is built on Checkmarx’ award-winning Fusion correlation engine and Application Risk Management, which already extracted unique insights from our consolidated AppSec platform, such as identifying reachable vulnerabilities. It now adds a new capability to Bring Your Own Results (BYOR) to expand coverage beyond Checkmarx’ award-winning solutions by importing SARIF and OSCF results from any third-party solution, including those from Checkmarx partners such as Zimperium, Onapsis and others.

With Checkmarx Cloud Insights, developers and AppSec leaders benefit from:

· Correlation and integration of Checkmarx data with data from cloud service providers (CSPs) and cloud-native application protection platforms (CNAPP).

· New ways to prioritize remediation, including through open-source libraries called in the runtime environment (via integration with Sysdig) and by internet-facing network exposure when deployed in the cloud environment (through partnerships with Wiz and Amazon Web Services.) The information is integrated within Checkmarx Application Risk Management.

· The ability to track remediation of a vulnerability through the software development life cycle (SDLC) by way of the attack path. For example, if a vulnerability is found in a running application, Cloud Insights:

· Identifies the repository and the developer to speed the process of remediation

· Pinpoints the container image to verify that the fix is reflected there

· Lists the running container clusters to enable verification that the running application was rebooted with fixed images and is no longer in the running environment.

· Improved developer experience with the delivery of prioritized risk intelligence that focuses developers on remediating vulnerabilities that are most critical, are most at risk of exploitation or that represent the greatest risk.

"Checkmarx One is the leading enterprise application security platform. By opening it to third-party results, our joint customers can easily extend their coverage and get a unified view within Checkmarx ASPM. We’re excited to partner with Checkmarx, which brings Zimperium’s leading mobile security threat insights directly into the Checkmarx Application Security Posture Management (ASPM) platform,” said Nitin Bhatia, Chief Strategy Officer at Zimperium. “This collaboration empowers an organization to manage and secure their entire mobile application landscape more effectively, ensuring comprehensive protection against emerging threats."

Beachhead Solutions launches ComplianceEZ

Posted 6 hours ago by Phil Alsop
Built into BeachheadSecure for MSPs, ComplianceEZ is said to be the only tool that can enforce and document 68 separate controls—satisfying 800...

Fluidstack selects VAST Data

Posted 3 days ago by Phil Alsop
The innovative AI-managed services provider will utilise the VAST Data Platform as it builds out infrastructure to meet enterprise-grade scale,...
Expanded guarantees give enterprises greater control, faster recovery from cyber threats and lower energy costs.
Generative integration leader brings the next evolution of AI-driven automation with new Prompt Composer and Agent Visualizer tools.

Kaseya unveils Spring 2025 innovations

Posted 3 days ago by Phil Alsop
Kaseya has launched its Spring 2025 release with new features that equips MSPs and internal IT teams with new capabilities to automate workflows,...

Informatica and Carnegie Mellon University partner

Posted 3 days ago by Phil Alsop
Informatica has formed a strategic partnership with Carnegie Mellon University (CMU) School of Computer Science, one of the world's foremost...
Fresh from a $50M round of investment, Unframe is now eyeing growth in the UK&I.
Nerdio Manager for MSP 6.0 delivers major innovations for automating, securing, and troubleshooting Microsoft 365 and AVD environments.