The Forrester Wave™: Static Application Security Testing, Q1 2021 the 12 Providers That Matter Most and How They Stack up by Sandy Carielli January 11, 2021
Total Page:16
File Type:pdf, Size:1020Kb
LICENSED FOR INDIVIDUAL USE ONLY The Forrester Wave™: Static Application Security Testing, Q1 2021 The 12 Providers That Matter Most And How They Stack Up by Sandy Carielli January 11, 2021 Why Read This Report Key Takeaways In our 28-criterion evaluation of static application Veracode, Synopsys, Checkmarx, And Micro security testing (SAST) providers, we identified Focus Lead The Pack the 12 most significant ones — CAST, Forrester’s research uncovered a market in Checkmarx, GitHub, GitLab, HCL Software, Micro which Veracode, Synopsys, Checkmarx, and Focus, Parasoft, Perforce Software, SonarSource, Micro Focus are Leaders; HCL Software and Synopsys, Veracode, and WhiteHat Security — CAST are Strong Performers; GitHub, Parasoft, and researched, analyzed, and scored them. This GitLab, Perforce Software, and SonarSource report shows how each provider measures up are Contenders; and WhiteHat Security is a and helps security and risk professionals select Challenger. the right one for their needs. Developer Enablement, New Architecture Support, And Accuracy Are Key Differentiators As development speeds continue to increase and teams embrace new development methodologies, SAST solutions that build security into the software development lifecycle (SDLC), regardless of how and where the application is built, will lead the pack. Vendors that offer deep integration with the CI/CD pipeline; quickly expand to protect new architectures like containers, APIs, and infrastructure-as-code (IaC); and continuously improve on performance and accuracy, position themselves to delight both security and developer stakeholders. This PDF is only licensed for individual use when downloaded from forrester.com or reprints.forrester.com. All other distribution prohibited. FORRESTER.COM FOR SECURITY & RISK PROFESSIONALS The Forrester Wave™: Static Application Security Testing, Q1 2021 The 12 Providers That Matter Most And How They Stack Up by Sandy Carielli with Amy DeMartine, Melissa Bongarzone, and Christine Turley January 11, 2021 Table Of Contents Related Research Documents 2 Next Generation SAST Solutions Focus On Build A Developer Security Champions Program Developer Enablement The Forrester Tech Tide™: Application Security, 2 Evaluation Summary Q4 2020 4 Vendor Offerings Now Tech: Static Application Security Testing, Q3 2020 5 Vendor Profiles Leaders Strong Performers Share reports with colleagues. Contenders Enhance your membership with Challengers Research Share. 11 Evaluation Overview Vendor Inclusion Criteria 12 Supplemental Material Forrester Research, Inc., 60 Acorn Park Drive, Cambridge, MA 02140 USA +1 617-613-6000 | Fax: +1 617-613-5000 | forrester.com © 2021 Forrester Research, Inc. Opinions reflect judgment at the time and are subject to change. Forrester®, Technographics®, Forrester Wave, TechRadar, and Total Economic Impact are trademarks of Forrester Research, Inc. All other trademarks are the property of their respective companies. Unauthorized copying or distributing is a violation of copyright law. [email protected] or +1 866-367-7378 FOR SECURITY & RISK PROFESSIONALS January 11, 2021 The Forrester Wave™: Static Application Security Testing, Q1 2021 The 12 Providers That Matter Most And How They Stack Up Next Generation SAST Solutions Focus On Developer Enablement Static application security testing (SAST) tools were initially built for security pros and neglected the needs of developers. As a result, developers were frustrated by false positives, lack of application context, and being forced out of their day-to-day workflows — and that frustration and friction hindered adoption. Happily, SAST vendors have shifted their thinking to include the developer as a key stakeholder in the application security process. Web application attacks were the top cause of external breaches in 2020, and SAST remains a critical tool to address vulnerabilities in proprietary code — as long as it continues to align with developer workflows and helps security pros prioritize and address application security weaknesses early in the SDLC.1 As a result of these trends, SAST customers should look for providers that: • Embrace the developer persona. SAST solutions must build into the developer experience, allowing developers to work efficiently in the tools that they already know. Look for SAST solutions that overlay the CI/CD pipeline through out-of-the-box-integrations with popular IDEs, build tools, and code repositories. In addition, seek solutions that provide actionable remediation guidance, with code samples and interactive training reachable through the developer’s toolset. • Go beyond the traditional definition of code. Firms don’t only build applications with traditional languages like C++ and Java or newer languages like Swift and Kotlin. APIs have become a common application building block, citizen developers have emerged to build apps using low-code platforms, and developers are using infrastructure-as-code (IaC) to define cloud configurations. As your firm’s definition of code expands, and as developers come from outside the traditional development organization, look for SAST tools that will scan for vulnerabilities in these new types of “code.” • Deliver accurate results quickly. Even as SAST has advanced with new features, the basic requirements of low false positives and short scan times remain. A number of customers still list accuracy and performance as challenges. Go beyond asking about false positive rates and performance metrics — ask what tuning is required out of the box and how to optimize scanning performance given your applications’ structure and architecture. Evaluation Summary The Forrester Wave™ evaluation highlights Leaders, Strong Performers, Contenders, and Challengers. It’s an assessment of the top vendors in the market and does not represent the entire vendor landscape. You’ll find more information about this market in our “Now Tech: Static Application Security Testing, Q3 2020” and “The Forrester Tech Tide™: Application Security, Q4 2020.” We intend this evaluation to be a starting point only and encourage clients to view product evaluations and adapt criteria weightings using the Excel-based vendor comparison tool (see Figure 1 and see Figure 2). Click the link at the beginning of this report on Forrester.com to download the tool. © 2021 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law. 2 [email protected] or +1 866-367-7378 FOR SECURITY & RISK PROFESSIONALS January 11, 2021 The Forrester Wave™: Static Application Security Testing, Q1 2021 The 12 Providers That Matter Most And How They Stack Up FIGURE 1 Forrester Wave™: Static Application Security Testing, Q1 2021 Static Application Security Testing Q1 2021 Strong Challengers Contenders Performers Leaders Stronger current offering Veracode Synopsys Micro Focus Parasoft Checkmarx CAST HCL Software SonarSource WhiteHat Security Perforce Software GitHub GitLab Weaker current offering Weaker strategy Stronger strategy Market presence © 2021 Forrester Research, Inc. Unauthorized copying or distributing is a violation of copyright law. 3 [email protected] or +1 866-367-7378 FOR SECURITY & RISK PROFESSIONALS January 11, 2021 The Forrester Wave™: Static Application Security Testing, Q1 2021 The 12 Providers That Matter Most And How They Stack Up FIGURE 2 Forrester Wave™: Static Application Security Testing Scorecard, Q1 2021 e e s ce Softwar ester’ o Focus eracode Forr weighting CAST CheckmarxGitHub GitLab HCL SoftwarMicr ParasoftPerfor SonarSouSynopsysrce V WhiteHaSecurityt Current offering 50% 2.78 3.36 1.41 1.32 2.75 3.30 3.22 2.20 2.30 3.74 3.65 2.25 Accuracy 20% 2.40 2.40 1.00 1.00 2.60 4.40 3.40 2.00 2.00 3.60 4.20 3.00 Remediation guidance 10% 3.00 5.00 3.00 1.00 1.00 3.00 1.00 1.00 1.00 5.00 5.00 3.00 and education Breadth of coverage 15% 3.00 4.20 0.80 2.60 4.20 3.00 0.80 0.80 1.80 3.00 4.60 1.00 Reporting 15% 3.00 2.00 1.00 1.00 2.00 3.00 5.00 4.00 3.00 3.00 4.00 3.00 Rule management 15% 4.60 4.00 2.70 1.00 4.00 3.80 3.80 2.80 2.80 3.80 1.80 0.50 Software development 25% 1.65 3.40 0.95 1.30 2.40 2.60 4.00 2.25 2.65 4.20 3.00 2.70 lifecycle integration Strategy 50% 2.65 4.54 3.70 3.30 3.90 3.81 1.80 2.40 1.81 4.21 4.40 1.11 Product vision 20% 3.00 5.00 5.00 3.00 5.00 5.00 1.00 3.00 3.00 5.00 5.00 3.00 Execution roadmap 15% 3.00 5.00 3.00 3.00 3.00 3.00 3.00 3.00 1.00 3.00 5.00 0.00 Market approach 25% 1.00 5.00 3.00 1.00 5.00 5.00 1.00 1.00 1.00 5.00 5.00 1.00 Planned enhancements 25% 5.00 5.00 3.00 5.00 3.00 3.00 3.00 3.00 1.00 5.00 5.00 0.00 Performance 15% 0.65 1.95 5.00 5.00 3.00 2.40 1.00 2.30 3.70 1.70 1.00 1.70 Market presence 0% 2.02 3.81 1.00 3.68 2.79 3.00 2.42 2.21 4.19 3.81 4.02 1.00 Install base 70% 1.60 3.30 1.00 4.40 2.70 3.00 2.60 2.30 4.70 3.30 3.60 1.00 Revenue 30% 3.00 5.00 1.00 2.00 3.00 3.00 2.00 2.00 3.00 5.00 5.00 1.00 All scores are based on a scale of 0 (weak) to 5 (strong). Vendor Offerings Forrester included 12 vendors in this assessment: CAST, Checkmarx, GitHub, GitLab, HCL Software, Micro Focus, Parasoft, Perforce Software, SonarSource, Synopsys, Veracode, and WhiteHat Security (see Figure 3). © 2021 Forrester Research, Inc.