Tuesday January 6, 2009 10:31 PM AEST
Latest Comments
"Discontinuing the issuance of MD5 certs is a good first step, but the real problem is that the ..."
by Scott | Jan 6, 2009 3:13 PM
 
"ineed nokia 6120c-1"
by Dipak Ahikari | Jan 6, 2009 2:04 PM
 
"My facebook profile has been hacked through one of these sites and they have changed my password ..."
by Ryan geen | Jan 3, 2009 3:51 PM
 
"http://impresser.com.au/category/security/ We need more websites like this. Security is an ..."
by Andrew Galdes | Dec 27, 2008 3:46 PM
 
"Um... what product were you really using???? documentation is supplied in printed form (aka a ..."
by Glen | Dec 23, 2008 12:11 PM
Web

IBM's Rational AppScan 7.7

  • Email a Friend
  • Print Page
IBM's Rational AppScan 7.7
Product Info
Supplier:
IBM
Product Rating
Features:  5
Ease of Use:  5
Performance:  5
Documentation:  5
Support:  4
Value for Money:  4
Overall Rating:  Overall Rating
 
For: Powerful scanning engine, robust set of options, excellent documentation
Against: True enterprise management requires the purchase of additional AppScan products
Verdict: A web application-assessment tool that delivers quality and value
By Nathan Ouellette
May 2, 2008 1:44 PM
Tags: IBM | RATIONAL | APPSCAN | 7.7
Like other stand-alone products, it is not an enterprise product in itself, but has a related group of Rational AppScan enterprise reporting and management products it can integrate with. We found the branding of the product has yet to be finalised, since the official brand is IBM Rational AppScan, but Watchfire's site still lists the product as Watchfire AppScan.

Installation is easy, as the product works with Windows 2000/XP/Vista/2003 and does not require a database backend. Licensing is automated and painless as well.

AppScan's interface allows for productive management and configuration of scans, results and reporting. As you would expect with a mature product, the interface is both easy to use for its intended audience as well as flexible enough to allow for robust customisation.

From a performance perspective, AppScan delivers a powerful scanning engine that exceeded expectations in our testing. The product can discover a wide range of vulnerabilities and supports a growing range of architectures, including Web 2.0 applications, Flash, Javascript, AJAX and more. AppScan has a wide array of options, including replay macros, a mechanism to easily report false positives and a simple but useful dashboard view of remediation tasks. Furthermore, the solution's compliance mapping and reporting features are excellent.

We felt that AppScan's documentation is outstanding. Included in the remediation sections are several web-based training modules. These consist of automated slide shows with narrative voiceover to help the user understand the vulnerability in greater detail. Although they may be aimed at less experienced security professionals, they add some nice value to the product.

Pricing for IBM Rational AppScan Standard Edition 7.7 starts at US$17,500 and is based on term licenses. Standard support is included with the product. Forum and user community support information on the product was challenging to find via the IBM Rational support site.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers