Ounce 4.2 Audit and Reporting Console Drives Security Compliance to the Line of Code
Waltham, MA, January 31, 2007 – Ounce Labs, the leader in software security assurance, today announced the release of Ounce 4.2, featuring the SmartAudit™ automated report generation for software security analysts, development managers, and risk management auditors. SmartAudit translates the results of Ounce’s extensive source code security analysis into comprehensive audit reports that measure compliance with software security best practices and regulatory requirements.
“There are a number of industry references for what constitutes secure software, so it’s often difficult for companies to demonstrate the security of their applications, whether in development, outsourced or in production,” said Brent Huston, CEO of MicroSolved. “By generating compliance reports automatically, Ounce’s SmartAudit enables users to quickly and thoroughly test their software at the code level and prove that it meets the requirements of auditors, partners, customers, or other key stakeholders. This helps us all make better business decisions when it comes to protecting critical data and resources.”
SmartAudit uses Ounce’s superior source code vulnerability analysis results to power a series of reports that provide a detailed picture of compliance to a security, development, or audit executive. Each SmartAudit report features:
The initial SmartAudit reports that will be offered include:
Ounce Labs will continue to develop additional reports for the SmartAudit suite in future releases according to changing software security requirements and industry demand.
“Smart Audit is groundbreaking because for the first time, developers will understand how their code affects compliance, and auditors will be able to better understand the root causes of many kinds of non-compliance,” said Jack Danahy, CTO and founder of Ounce Labs. “This is a unique and significant advantage to organizations that want to develop and run certifiably secure software.”
Ounce 4.2 will be generally available on February 28, 2007.
About Ounce Labs, Inc.
Ounce Labs™, the leader in software security assurance, delivers products that enable customers to manage software risk in applications across the enterprise, traceable down to individual lines of code. The Ounce solution features patents-pending source code analysis technology, which scans source code to pinpoint programming errors, design flaws, and policy violations. Ounce offers the most accurate and complete software vulnerability results, the fastest time-to-results, the only complete application portfolio management, and the greatest deployment flexibility. Customers using the Ounce software security solution include leading organizations in financial services, telecommunications, software development, government, and other industries focused on protecting data, reducing software vulnerabilities, and complying with industry regulations. Ounce Labs is headquartered in Waltham, Massachusetts, with regional offices throughout the U.S. For more information, please visit www.ouncelabs.com.
###
CONTACT:
Ounce Labs
Jake Messier
781.547.7031 (o)
774-368-0094 (m)
jake.messier@ouncelabs.com
"Security scanners tend to be trigger happy and obtuse, but Ounce Labs offers friendly scanners with fewer false alarms."