Published: 26 April 2022
Summary
Secure software is key to a modern enterprise, and is increasingly required by boards, regulators and developers. Amid evolving development styles and application architectures, IT leaders must work with engineering and business teams to automate security tests for the whole application portfolio.
Included in Full Research
Overview
Key Findings
In 2022, the application security testing (AST) market is expanding beyond static and dynamic AST (SAST/DAST). Across the AST landscape, we are increasingly seeing new tools enter the market. Tools for infrastructure as code (IaC), container security, API management and other features are becoming mainstream requirements.
Development teams and security teams are increasingly cooperating on security, trying to balance requirements for secure products with positive developer experiences that fit into their workflow.
Cloud and containerized projects, long relegatedto experiments and prototypes, are finally moving into full production for many organizations. They bring with them a new attack surface, new tools
Clients can log in to view the entire
document.
- Checkmarx
- Contrast Security
- Data Theorem
- GitHub
- GitLab
- HCL Software
- Invicti
- Micro Focus
- NTT Application Security
- Onapsis
- Rapid7
- Snyk
- Synopsys
- Veracode
- Static AST
- Dynamic AST
- Interactive AST
- Software Composition Analysis
- Mobile AST
- Business-Critical Applications
- API Testing and Discovery
- Infrastructure as Code
- Container Security Scanning
- Fuzzing
- Life Cycle Integration
- Developer Enablement
- Enterprise
- Continuous Testing
- Mobile and Client
- DevSecOps
- Cloud-Native Applications
Gartner Recommended Reading
Critical Capabilities Methodology