{"id":25669,"date":"2018-10-26T10:30:57","date_gmt":"2018-10-26T09:30:57","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=25669"},"modified":"2018-10-26T10:30:57","modified_gmt":"2018-10-26T09:30:57","slug":"ca-veracode-reveals-latest-state-of-software-security-report","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/10\/26\/ca-veracode-reveals-latest-state-of-software-security-report\/","title":{"rendered":"CA Veracode reveals latest State of Software Security report"},"content":{"rendered":"<p>CA Veracode, part of CA Technologies&#8217;\u00a0 industry-leading security portfolio, has released the latest State of Software Security (SOSS) report.<\/p>\n<p>The study includes promising signs that\u00a0DevSecOps\u00a0is facilitating better security and\u00a0efficiency, and\u00a0provides the industry with the company\u2019s first look at flaw persistence analysis, which measures the longevity of flaws after first discovery. Businesses in the UK outperformed most regions in finding and fixing flaws in their software, but most European nations\u00a0analysed\u00a0fell well behind in remediation.<\/p>\n<p><strong>The state of software security is improving\u00a0<\/strong><\/p>\n<p>In every industry,\u00a0organisations\u00a0are dealing with a massive volume of open flaws to address and they are showing improvement in\u00a0taking action\u00a0against what they find. According to the report, 69% of flaws discovered were closed through remediation or mitigation, an increase of nearly 12% since the previous report. This shows\u00a0organisations\u00a0are gaining prowess in closing newly discovered vulnerabilities, which hackers often seek to exploit.<\/p>\n<p>Despite this progress, the new SOSS report also shows that the number of vulnerable apps remains staggeringly high and open source components continue to present significant risks to businesses.<\/p>\n<p>More than 85% of all applications contain at least one vulnerability following the first scan and more than 13% of applications contain at least one very high severity flaw. In addition,\u00a0organisations\u2019\u00a0latest scan results indicate that one in three applications were vulnerable to attack through high or very high severity flaws.<\/p>\n<p>An examination of fix rates across two trillion lines of code shows that companies face extended application risk exposure due to persisting flaws:<\/p>\n<ul>\n<li>More than 70% of all flaws remained one month after discovery and nearly 55% remained three months after discovery<\/li>\n<li>A total of 25% of high and very high severity flaws were not addressed within 290 days of discovery<\/li>\n<li>Overall, 25% of flaws were fixed within 21 days, while the final 25% remained open, well after a year of discovery<\/li>\n<\/ul>\n<p>\u201cSecurity-minded\u00a0organisations\u00a0have\u00a0recognised\u00a0that embedding security design and testing directly into the continuous software delivery cycle is essential to achieving the\u00a0DevSecOps\u00a0principles of balance of speed, flexibility and risk management. Until now, it\u2019s been challenging to pinpoint the benefits of this approach but this latest State of Software Security report provides hard evidence that\u00a0organisations\u00a0with more frequent scans are fixing flaws more quickly,\u201d said Chris\u00a0Eng, Vice President of Research, CA Veracode. \u201cThese incremental improvements amount over time to a significant advantage in competitiveness in the market and a huge drop in risk associated with vulnerabilities.\u201d<\/p>\n<p><strong>Regional differences in flaw persistence\u00a0<\/strong><\/p>\n<p>While data from US organisations\u00a0dominate the sample size, this year\u2019s report offers insights into differences by region in how quickly vulnerabilities are being addressed.<\/p>\n<p>The UK was among the strongest performing regions: businesses there closed the first 25% of their flaws in just 11 days, second fastest among all regions, closed 50% of flaws in 72 days and closed 75% of flaws in 304 days. These marks outpaced averages across regions.<\/p>\n<p>Companies in Asia Pacific (APAC) are the quickest to remediate, closing out 25% of their flaws in about eight days, followed by 22 days for the Americas and 28 days for those in Europe and the Middle East (EMEA). However, companies in the US and the Americas caught up, closing out 75% of flaws by 413 days, far ahead of those in APAC and EMEA.<\/p>\n<p>In fact, it took more than double the average time for EMEA\u00a0organisations\u00a0to close out three-quarters of their open vulnerabilities. Troublingly, 25% of vulnerabilities in\u00a0organisations\u00a0in EMEA persisted more than two-and-a-half years after discovery.<\/p>\n<p><strong>Data supports\u00a0DevSecOps\u00a0practices\u00a0<\/strong><\/p>\n<p>In its third consecutive year documenting\u00a0DevSecOps\u00a0practices, the SOSS analysis shows a strong correlation between high rates of security scanning and lower long-term application risks, presenting significant evidence for the efficacy of\u00a0DevSecOps.<\/p>\n<p>CA Veracode\u2019s data on flaw persistence shows that\u00a0organisations\u00a0with established\u00a0DevSecOps\u00a0programs and practices greatly outperform their peers in how quickly they address flaws. The most active\u00a0DevSecOps\u00a0programs fix flaws more than 11.5 times faster than the typical\u00a0organisation, due to ongoing security checks during continuous delivery of software builds, largely the result of increased code scanning. The data shows a very strong correlation between how many times a year an\u00a0organisation\u00a0scans and how quickly they address their vulnerabilities.<\/p>\n<p><strong>Open source components continue to thwart enterprises\u00a0\u00a0<\/strong><\/p>\n<p>In prior SOSS reports, data has shown that vulnerable open source software components run rampant within most software. The current SOSS report found that most applications were still rife with flawed components, though there has been some improvement on the Java front.<\/p>\n<p>Whereas last year about 88% of Java applications had at least one vulnerability in a component, it fell to just over 77% in this report. As\u00a0organisations\u00a0tackle bug-ridden components, they should consider not just the open flaws within libraries and frameworks, but also how they are using those components.<\/p>\n<p>By understanding not just the status of the component, but\u00a0whether or not\u00a0a vulnerable method is being called,\u00a0organisations\u00a0can pinpoint their component risk and\u00a0prioritise\u00a0fixes based on the riskiest uses of components.<\/p>\n<p><strong>About the State of Software Security report\u00a0<\/strong><\/p>\n<p>This is CA Veracode\u2019s ninth iteration of the State of Software Security (SOSS) report, a comprehensive review of application security testing data from scans of more than two trillion lines of code conducted by CA Veracode\u2019s base of 2,000 customers representing the industry&#8217;s most comprehensive set of application security benchmarks.<\/p>\n<p>The report investigated variables such as flaw type, severity, app criticality, rate of scanning impact on fix velocity, and persistence of flaws after discovery. For this iteration, CA Veracode collaborated with data scientists at\u00a0Cyentia Institute\u00a0to better\u00a0visualise\u00a0and understand vulnerability fix behaviour.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CA Veracode, part of CA Technologies&#8217;\u00a0 industry-leading security portfolio, has released the latest State of Software Security (SOSS) report. The study includes promising signs that\u00a0DevSecOps\u00a0is facilitating better security and\u00a0efficiency, and\u00a0provides the industry with the company\u2019s first look at flaw persistence analysis, which measures the longevity of flaws after first discovery. Businesses in the UK outperformed [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":25672,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,14,6617,29],"tags":[9616,410,9617,9618,9619,8175,7,114,9620,6760,9621,9622,5006,8563,9623],"class_list":["post-25669","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-more-news","category-research","category-software","tag-americas","tag-apac","tag-ca-veracode","tag-chris-eng","tag-cyentia-institute","tag-devsecops","tag-emea","tag-hackers","tag-java","tag-software-2","tag-soss","tag-state-of-software-security","tag-uk","tag-us","tag-vice-president-of-research"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/25669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=25669"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/25669\/revisions"}],"predecessor-version":[{"id":25671,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/25669\/revisions\/25671"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/25672"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=25669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=25669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=25669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}