March 03, 2008 — CSO —
| Cenzic | HP(SPI) | IBM (Watchfire) | NTOBJECTIVES | WhiteHat | |
| Product or Service | Either | Either | Either | Either | Service only |
| Installation (Centralized or Desktop/ Distributed) | Either | Either | Either | Either | N/A (hosted service) |
| Reporting Formats | CSV, DOC, HTML, PDF, RTF | HTML and PDF or direct from SQL database | DOC, PDF, PPT, XML; Reporting console supports CSV, DOC, PDF, XLS, XML | HTML, XML or direct from SQL database | HTML, PDF, XML |
| QA/Testing Integration | Integrates with Borland and HP Quality Center | Integrates with HP QA Inspect, HP Quality Center, IBM Rational ClearQuest, Microsoft Visual Studio TeamSystem | Integrates with IBM Rational ClearQuest, HP QualityCenter and Microsoft Visual Studio TeamSystem | No | Via API |
| Static Source Code Analysis Tool Integration | Integrates with Fortify SCA and Ounce Labs | Integrates with HP (SPI) DevInspect; Partnerships with Veracode and Ounce Labs | Integrates with Fortify SCA | Static binary analysis, Veracode | N/A |
| Web Application Firewall (WAF) Integration | Integrates with Netcontinuum | Integrates if WAF supports AVDL | No | No | N/A |
| Manual Penetration Testing Support | Tester-configured Smart Attacks | HP (SPI) Security Toolkit | AppScan eXtensions Framework, Watchfire PowerTools and ability to manage third-party tools from the AppScan console | Tester-configured manual crawling, XML attacks and fuzzing | Service includes manual penetration testing |
Read more about other in CSOonline's Other section.
White Papers
Sponsored Links
More Salted Hash with Bill Brenner