
Explore the course agenda for application security with Fortify on Demand, covering theory, hands-on onboarding and scanning, and integrations from IDE to GitHub, including AST, DAST, and SAST.
explore core terminology in application security, including ci/cd, sdlc, devops, devsecops, dast, sast, sca, and monolithic versus microservices architectures.
Analyze the market leaders in application security testing, including Fortify and OpenText with Sast and Web Inspect, and track Gartner Magic Quadrant changes from 2021 to 2023.
Explore Fortify on Demand, a complete Appsec as a service with static analysis, software composition analysis, and dynamic testing integrated into DevOps pipelines, plus its assessment units and subscriptions licensing.
Learn how to request Fortify on Demand trial license, understand the 15-day limit and two static scans, and set up access using a business domain and email.
Explore the FoD portal workflow, including applications and releases, scans, dashboards, and reports, then dive into policy management, entitlements, and imported demo data.
Onboard an application in Fortify on Demand, create the release, set attributes, assign user groups, and configure static and dynamic scans with the right entitlements and authentication settings.
Demonstrates how to integrate Fortify on Demand with the Visual Studio IDE by installing the extension, configuring Scan Central, packaging code, and uploading builds to view results in the IDE.
Set up GitHub CI/CD integration with Fortify on Demand by configuring secrets and a workflow, then run a static scan on a Java project and review the results.
Learn to establish FoD connect, enabling Fortify on Demand scanners to reach internal applications via a VPN, using a VM with OpenVPN and Docker to support dynamic scans.
Application security testing (AST) is all about identifying and fixing vulnerabilities in software applications. It ensures that apps are secure from various threats throughout their lifecycle, from development to deployment and beyond. There are several types of AST, like Static Application Security Testing (SAST) which examines the source code, and Dynamic Application Security Testing (DAST) which tests running applications. Think of it as a thorough health check-up for your software!
OpenText™ Fortify™ On Demand (hereafter referred to as "FoD") offers application security (AppSec) as a service providing customers with their own cloud-based tenant
FoD includes all essential tools that enable customers to streamline their Software Security Assurance Programs in a way that is effective and efficient at the same time.
FoD is an enabler for DevSecOps best practices towards secure development and continuous feedback at DevOps speed
Opentext claims that FoD is the only application security provider offering SAST, SCA, DAST, IAST, and MAST as services and is capable for rapidly resolve issues throughout the SDLC efficiently, supported by thorough assessments from security experts.
In a nutshell, FoD utilizes a user-friendly integration ecosystem to fortify customers' software supply chain and support scalable maturity.
In this course you will learn the following:
Section I - Theoretical
• Course Agenda
• Terminology
• Market Analysis
• Fortify on demand Overview and Licensing model
Section II – Hands-On
• Requesting FoD Trial License
• FoD Portal Walk-through
• Application On-boarding and Scan Setup
Section III – Integrations
• Visual Studio IDE Integration
• GitHub CI/CD Pipeline Integration
• FoD Connect