Security News > 2021 > August > Increasing speed of vulnerability scans ultimately increases security fixes overall

Next-generation static application security testing and intelligent software composition analysis can increase the speed of vulnerability scans and narrow their scope to highlight reachable issues, a ShiftLeft report reveals.
This ultimately leads to measurably better outcomes: more frequent scans, fix rates earlier in the CI/CD pipeline that prevent security debt from accruing, and more security fixes overall.
The report reveals that tightly integrating security testing with the CI/CD pipeline results in better outcomes that will be critical as the world continues to rely on digital services and enterprises accelerate security transformation.
Vulnerability scans speed is key Speed and frequency of scans - While legacy security analysis tools can take hours or even days to conduct a full scan, ShiftLeft customers experienced a median scan time of 2 minutes and 20 seconds.
When open source vulnerabilities are prioritized by accounting for true "Reachability," organizations reduce the number of their SCA tickets by an average of 92%. Fix-rates for managed CI/CD - When increasing the speed and frequency of scans and prioritizing SCA tickets, ShiftLeft found enterprises that tightly integrate security testing within their CI/CD pipeline fix 91.4% of new issues.
Security fixes by type - As organizations fix a higher number of vulnerabilities in their applications, 86% of these fixes were for critical or well-known issue classes.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/bFMHqycUbtU/