R&D at a tech services company with 51-200 employees
Real User
Effective on-demand feature, easy to use cloud, and great support
Pros and Cons
  • "There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do."

    What is our primary use case?

    We are using Micro Focus Fortify on Demand because in the beginning we were using the on-premise version and it was very limited. We thought we could do everything wanted with the on-premise solution. However, it was not easy to use. 

    We are testing the Micro Focus Fortify on Demand solution to improve security.

    We are using the on-premise version of this solution for the static code for developers. For the dynamic code, we're using Micro Focus Fortify on Demand.

    What is most valuable?

    There is not only one specific feature that we find valuable. The idea is to integrate the solution in DevSecOps which we were able to do. We were working with a different solution called SolarCloud previously and it was limited. We are trying to find the right level of security for our needs.

    For how long have I used the solution?

    I have been using Micro Focus Fortify on Demand for approximately eight months.

    How are customer service and support?

    The support is good. Their support is in the Netherlands, sometimes it takes some time for the time zone difference between Latin America and the Netherlands but overall the support is good.

    Buyer's Guide
    Application Security Tools
    January 2024
    Find out what your peers are saying about OpenText, Sonar, Checkmarx and others in Application Security Tools. Updated: January 2024.
    756,650 professionals have used our research since 2012.

    How was the initial setup?

    The implementation of Micro Focus Fortify on Demand was simple, since it is on the cloud everything is automatic. They give you an account and that is all, you use the product.

    The premise solution is more rentable. However, it is asking for a lot of effort in the implementation, administration, and integration in the pipeline. It takes time until the company comes to the right level to be able to manage this product. Even with the right partners in Latin America that work with us, it took some time.

    What about the implementation team?

    We had partners in Latin America that help us integrate the implementation of the Micro Focus Fortify on Demand.

    What's my experience with pricing, setup cost, and licensing?

    The solution is expensive and the price could be reduced.

    What other advice do I have?

    My advice to others is if you choose Micro Focus Fortify on Demand, it's very simple to use. If they choose the on-premise version for the static code, they will need a person to manage it to be sure that it's integrated with all the pipelines that they developed. 

    I rate Micro Focus Fortify on Demand a seven out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Security Information Manager at a tech services company with 10,001+ employees
    Real User
    Solid usability for security and vulnerability issues
    Pros and Cons
    • "The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues."
    • "In terms of what could be improved, we need more strategic analysis reports, not just for one specific application, but for the whole enterprise. In the next release, we need more reports and more analytic views for all the applications. There is no enterprise view in Fortify. I would like enterprise views and reports."

    What is our primary use case?

    I use it for SAST, security analysis static code.

    What is most valuable?

    The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues.

    What needs improvement?

    In terms of what could be improved, we need more strategic analysis reports, not just for one specific application, but for the whole enterprise.

    In the next release, we need more reports and more analytic views for all the  applications. There is no enterprise view in Fortify. I would like enterprise views and reports.

    For how long have I used the solution?

    I am using Micro Focus Fortify on Demand for one year.

    What do I think about the stability of the solution?

    It is very stable.

    What do I think about the scalability of the solution?

    It is scalable. Micro Focus Fortify on Demand requires a big hardware with a big processing capacity, but it is scalable.

    How are customer service and support?

    Their customer support is very good. I sometimes need it, and I get the answer quickly. They are very helpful.

    How was the initial setup?

    The initial setup is not so easy, but not so difficult. I would say it is medium difficulty.

    What other advice do I have?

    On a scale of one to ten, I would give Micro Focus Fortify on Demand an eight.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Application Security Tools
    January 2024
    Find out what your peers are saying about OpenText, Sonar, Checkmarx and others in Application Security Tools. Updated: January 2024.
    756,650 professionals have used our research since 2012.
    it_user488193 - PeerSpot reviewer
    System Engineer at a tech services company with 501-1,000 employees
    Consultant
    Both editions of the product have their advantages, and they complement each other.

    What is most valuable?

    Both editions of the product have their advantages, and they complement each other.

    How has it helped my organization?

    Since we adopted HP Fortify, our organization has added more divisions that focus on penetration testing.

    What needs improvement?

    HP Fortify already covers the need for security testing and is easy to use for new users. The only thing that comes to mind regarding room for improvement are the security vulnerability updates.

    For how long have I used the solution?

    My company has been using this solution for about one year.

    What was my experience with deployment of the solution?

    I have not encountered any deployment, stability or scalability issues. I haven't had any complaints about technical issues from our client, either.

    How are customer service and technical support?

    I have not yet contacted customer service or technical support.

    Which solution did I use previously and why did I switch?

    I do know of some software that have similarities, but I’ve never used any of them before.

    How was the initial setup?

    Most of our clients use straightforward implementation; we recommend straightforward implementation because of the simplicity of the architecture and usage. For example, installing using the best practices for each product.

    What about the implementation team?

    We implemented it for our customer.

    What other advice do I have?

    HP Fortify is perfect for any company that creates their own applications or uses vendor-developed ones; it’s great for QA and development phases.

    HP Fortify is easy to use and offers lots of integration options; those options allow us to have more diverse implementations that fit the requirements.

    Disclosure: My company has a business relationship with this vendor other than being a customer: My company distributes HP Fortify.
    PeerSpot user
    Head of Compliance & Quality / CISO at a tech services company with 51-200 employees
    Real User
    Has improved our security through static code analysis
    Pros and Cons
    • "The static code analyzers are the most valuable features of this solution."
    • "The reporting capabilities need improvement, as there are some features that we would like to have but are not available at the moment."

    What is our primary use case?

    Our primary use case for this solution is static code analysis.

    How has it helped my organization?

    This solution has helped us to improve our security processes.

    What is most valuable?

    The static code analyzers are the most valuable features of this solution.

    What needs improvement?

    The reporting capabilities need improvement, as there are some features that we would like to have but are not available at the moment. It needs a better configuration and more options for reports.

    For how long have I used the solution?

    Four months.

    What do I think about the stability of the solution?

    The solution is working, so I would say that its stability is fine.

    What do I think about the scalability of the solution?

    We have approximately twenty users who perform code scanning. They are developers and security experts. We do plan to increase our usage of this solution in the future.

    How are customer service and technical support?

    Technical support for this solution is fine.

    How was the initial setup?

    The initial setup of this solution is straightforward.

    It took approximately two hours to deploy, and because it is a cloud-based solution it does not require anybody for maintenance.

    What about the implementation team?

    We handled the implementation in-house.

    What was our ROI?

    All I can say is that it is reducing security issues.

    Which other solutions did I evaluate?

    We evaluated Veracode before choosing this solution.

    What other advice do I have?

    This solution works, so I suggest using it.

    I would rate this solution an eight out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user362055 - PeerSpot reviewer
    Senior Manager at a tech services company with 10,001+ employees
    Real User
    It addresses the source code scanning and dynamic scanning in a known, correlated way.

    Valuable Features

    It's one of the leaders in the application security space. I've used Fortify since 2007, and I think the most valuable feature is its ability to address the source code scanning and dynamic scanning in a known, correlated way. I think the best way to address application security is to have multiple types of scanning and a unified view for the customer.

    Improvements to My Organization

    It's forced the incorporation of security in the development process. That's really the biggest benefit for us.

    Room for Improvement

    It could use better integration with the incident management processor. This would allow us to understand the vulnerabilities that arise in the software and how they're linked to the incident management center.

    Deployment Issues

    The deployment has not had issues.

    Stability Issues

    It is a quite stable solution.

    Scalability Issues

    It's quite scalable and addresses a huge volume.

    Customer Service and Technical Support

    It's good, but could be better to align with other main vendors, such as IBM.

    Initial Setup

    It's not straightforward, but it's not complex either. It could also be improved.

    Other Solutions Considered

    I'm very familiar with IBM and Barracuda and others. I always know HP's competition, but I feel most comfortable with HP.

    Other Advice

    My advice would be to look not only at the software, but also at the processor and the people who will be using the software. You should buy not just the software, but also the services to train people to use it.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user310152 - PeerSpot reviewer
    it_user310152Fortify Business Development at a tech vendor with 10,001+ employees
    Vendor

    In terms of integration with SIM/SIEM solution, what do you use?

    Information Security Manager at a tech services company with 501-1,000 employees
    Real User
    Easy to set up, stable and scalable
    Pros and Cons
    • "It's a stable and scalable solution."
    • "Reporting could be improved."

    What is our primary use case?

    We use Micro Focus Fortify on Demand to access web applications and more.

    What needs improvement?

    Reporting could be improved. It would nice to export to an Excel sheet or another spreadsheet. At the moment, my only option is a PDF.

    Micro Focus Fortify on Demand is tailored towards more web application APIs, and I would like to see mobile applications added to the next release.

    For how long have I used the solution?

    We've been using Micro Focus Fortify on Demand for almost two years.

    What do I think about the stability of the solution?

    Focus Fortify on Demand is a stable solution.

    What do I think about the scalability of the solution?

    Focus Fortify on Demand is a scalable solution. 

    How was the initial setup?

    The setup and installation were straightforward. 

    What other advice do I have?

    On a scale from one to ten, I'll give it an eight.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Application Security Tools Report and find out what your peers are saying about OpenText, Sonar, Checkmarx, and more!
    Updated: January 2024
    Buyer's Guide
    Download our free Application Security Tools Report and find out what your peers are saying about OpenText, Sonar, Checkmarx, and more!