This research note is restricted to the personal use of
[email protected]. Magic Quadrant for Application Security Testing Published: 29 April 2020 ID: G00394281 Analyst(s): Mark Horvath, Dionisio Zumerle, Dale Gardner Modern application design and the continued adoption of DevSecOps are expanding the scope of the AST market. Security and risk management leaders will need to meet tighter deadlines and test more complex applications by seamlessly integrating and automating AST in the software delivery life cycle. Strategic Planning Assumptions By 2025, 70% of attacks against containers will be from known vulnerabilities and misconfigurations that could have been remediated. By 2025, organizations will speed up their remediation of coding vulnerabilities identified by SAST by 30% with code suggestions applied from automated solutions, up from less than 1% today, reducing time spent fixing bugs by 50%. By 2024, the provision of a detailed, regularly updated software bill of materials by software vendors will be a non-negotiable requirement for at least half of enterprise software buyers, up from less than 5% in 2019. Market Definition/Description Gartner’s view of the market is focused on transformational technologies or approaches delivering on the future needs of end users. Gartner defines the application security testing (AST) market as the buyers and sellers of products and services designed to analyze and test applications for security vulnerabilities. We identify four main AST technologies: ■ Static AST (SAST) technology analyzes an application’s source, bytecode or binary code for security vulnerabilities, typically at the programming and/or testing software life cycle (SLC) phases. This research note is restricted to the personal use of
[email protected].