Saturday | 6 September, 2008
Computerworld
Oracle turns to Fortify to secure source code
Startup source-code security technology developer Fortify scored a major triumph as Oracle announced plans to use Fortify's tools in its development process.
Stacy Cowley (IDG News Service) 21/12/2005 08:09:33

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Startup source-code security technology developer Fortify Software scored a major triumph on Tuesday as Oracle announced plans to use Fortify's tools to seek out holes in Oracle's database and middleware software.

Oracle Chief Security Officer Mary Ann Davidson said she searched for years for automated tools to examine Oracle's source code but had been unimpressed with the available products. Fortify was the first company to listen to Oracle's description of its development process and to tailor its software to meet Oracle's needs, Davidson said.

Oracle has a code base of more than 30 million lines, and is the first top-tier commercial software developer to sign on as a Fortify customer. Other Fortify clients include a number of financial services companies, as well as Flash maker Macromedia. Identity management software developer Oblix, acquired by Oracle earlier this year, was also a customer, but Davidson said Oracle's work with Fortify predated its Oblix buy.

Fortify's software is an integrated collection of tools that scan code for secure coding policy violations and other weaknesses. Oracle has licensed the tools for its Server Technologies group, which handles development of its database, application server, identify management and collaboration suite software. Oracle's application software, including its E-Business Suite and the products Oracle acquired from PeopleSoft and other vendors, is written in a variety of programming languages and isn't a good fit for Fortify's tools, and will not be included in the deal, Davidson said.

Oracle, based in California, hopes that by eliminating vulnerabilities before code turns into shipped product, it will reduce the number of patches it needs to issue and improve its customers' security.

"There's lots of band-aid products out there that protect against attacks. You wouldn't need so many band aids if you could actually have a vaccine," Davidson said.

Oracle, which once used "unbreakable" as its brand slogan, has taken a few hits on its security reputation this year after issuing a spate of critical patches. A German security firm published details of several high-risk vulnerabilities in Oracle's software after the firm said it tried for years to draw Oracle's attention to the security holes.

Fortify is a private, venture capital-backed vendor with headquarters in California. The company launched last year and now has around 50 employees. Winning Oracle's business will be a major boost to Fortify's credibility as it looks to convince more large vendors to license its security tools.

Working with Oracle has helped Fortify refine its first-generation software and improve its tools' performance, Fortify Chief Executive Officer John Jack said.

"We now have a product that scales to the largest code base," Jack said. "It's been a great year."

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

SOA and Agility

Organizations need agility to maintain strategic advantages in businesses operating on faster and faster time-scales. The difference between gaining and losing market share may very well depend on the ability of organizations to deploy updated or new applications before their competitors. Read on to discover how SOA-based application development can meet the promise of reduced application development and maintenance costs through service reuse.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links