RFP Sast: SWOT Analysis: Checkmarx
RFP Sast: SWOT Analysis: Checkmarx
RFP Sast: SWOT Analysis: Checkmarx
md 28/06/2022
RFP SAST
Strengths
Weakness
Opportunities
* None
Threats
Strengths
1/5
RFP_SAST.md 28/06/2022
Weakness
Opportunities
* Ease of use for GitHub users -> Github is well adopted by dev's
* Results are displayed during a pull request -> Continuos check's
* GitHub code scanning can import SARIF from any other SAST tool
Threats
Strengths
Weakness
2/5
RFP_SAST.md 28/06/2022
Opportunities
Threats
Strengths
Weakness
Opportunities
Threats
* None
Strengths
* Has a consistent level of quality and ease of use across its toolset
Weakness
Opportunities
* None
Threats
Conclusion
Integrating security into DevOps is a delicate challenge for AppSec professionals. However, one thing is for
certain: if developers are asked to scan their code and the tool that they’re provided with doesn’t deliver fast
frictionless results, they’ll be less inclined to use it or resist it altogether. By providing the fastest scans
possible, friction can be eased and adoption accelerated, improving the relationship between developers and
4/5
RFP_SAST.md 28/06/2022
AppSec teams. That's why WhiteHat Security will not be considered. Github is also out of race since is to tight
with there own ecosystem. The solution must run on premise with our gitlab instance. Since our data
regulations require that the code does not leave the university servers, snyk is also out of the running. The
two remaining candidates are Checkmarks and Microfocus.
Both candidate are very promising but in the end we choose just one for the PoC. Microfocus and
Checkmarks are both comparable in its features and results. Our regulations demand that the code stay's
inhouse. So the solution has to be completly on premise. The announcement of Checkmarks that the could go
the Saas only is a no go.
5/5