English   Deutsch

Product Report: Virtual Forge CodeProfiler - 70583

Code security analysis has become one of the most important business segments servicing the secure development of software. Products are pretty mature for every mainstream programming language, and large IT companies have acquired the major technology innovators in that segment.

There is, though, an area of software development that receives little attention, although being quite important for businesses: the so-called customizing of SAP applications. Customization in SAP applications typically means that new application pieces will be added to the SAP standard offering. In many cases existing modules and functionalities will be rewritten at the customer site to optimize their usage for the customer specific business processes. As such, the customization is actually more a development activity and thus may greatly benefit from code security analysis, specifically for compliance purposes.

Most SAP customization projects, though, will take place in SAP’s ERP application suite, and this is mostly written in SAP’s proprietary language called ABAP. There are only a few companies that offer code analysis for ABAP programs, let alone analysis of the security of the developed code. Virtual Forge fills this niche with its flagship product CodeProfiler that analyzes SAP ABAP code for vulnerabilities and, optionally, also for other code quality aspects.

CodeProfiler has reached a mature status, and is currently in the phase of feature enrichment, so beyond the capabilities presented today (excellent performance, easy configuration, predefined content, full integration into SAP development activities) there will be more beneficial functionalities available soon. The ecosystem has reached a good level of maturity with worldwide sales and consulting through SAP and IBM and specific mid-market solution OEM packages.
Security for SAP applications is hard to mandate in real life due to its relatively central but isolated position in most organizations, and even then most IT specialists understand “SAP security” to be limited to good authorization management. Nevertheless, the modification of SAP software poses a high business risk and should therefore be treated with equal care. It is therefore important to establish (business) stakeholders for SAP security before being able to fully leverage the value of CodeProfiler.

Overall, Virtual Forge CodeProfiler is an excellent solution for a small but important niche, and SAP customers that are taking the risk of code vulnerabilities seriously shall consider the product for an evaluation.



Date Title Price
29.03.12 Product Report: Virtual Forge CodeProfiler - 70583


€295.00 GET ACCESS 
top
KuppingerCole Select
Register now for KuppingerCole Select and get your free 30-day access to a great selection of KuppingerCole research materials and to live trainings.
Register now
Research
KuppingerCole CIO GPS
The KuppingerCole CIO GPS shows the nine areas CIOs should focus on for IT Spend Optimization, Business IT/Alignment, and Strategic Procurement, when looking at GRC (Governance, Risk Management, Compliance) and Information Security. GPS stands for Governance, Privacy and Data Protection, and Security.
KuppingerCole BII: The Business Impact Indicator
The KuppingerCole BII is a Business Impact Indicator for Information Technology. It shows the business value a particular technology or initiative can deliver, in a single and clearly laid out graphic. It complements other KuppingerCole research methodology that shows which technologies are best for achieving the targets in IT Spend Optimization, Business/IT Alignment, and Strategic Procurement.
Services
KuppingerCole Analyst Services
In the networked economy of the 21st century, digital identities play a key role in establishing trust, achieving security, lowering costs and making business processes more efficient. Things like Identity and Access Management (IAM) or...
KuppingerCole Vendor Services
The market for Identity and Access Management (IAM), governance, risk management, and compliance (GRC) and cloud computing is expanding by leaps and bounds. In fact, no other segment of the IT market can boast such dynamic growth rates. At the...
KuppingerCole Briefings
KuppingerCole welcomes the opportunity to hear from IT companies when they launch a new product or service or have other interesting progress to announce. Please fill in the request form , and we will contact you shortly. 
Links
 KuppingerCole News

 KuppingerCole on Facebook

 KuppingerCole on Twitter

 KuppingerCole on Google+

 KuppingerCole at LinkedIn

 Our group at LinkedIn

 Our group at Xing

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2013 KuppingerCole