• Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

Why Conversational Commerce is the Future of Shopping

May 29, 2025

10 Leadership Myths You Need to Stop Believing

May 29, 2025

Tesla’s Layoffs Won’t Solve Its Growing Pains

May 29, 2025
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
InDirectica
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
InDirectica
Home » Lacework Expands into Full Application Lifecycle Protection
Innovation

Lacework Expands into Full Application Lifecycle Protection

adminBy adminNovember 15, 20230 ViewsNo Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Cloud security provider Lacework announced the extension of its platform to include code security, enhancing its coverage of the full application lifecycle. The new features provide Lacework customers with comprehensive visibility throughout the application development process, helping to identify and address security issues before deployment.

Lacework introduced new Software Composition Analysis (SCA) and Static Application Security Testing (SAST) capabilities, providing significant additions to its platform. Let’s look at each in turn.

Software Composition Analysis

Lacework’s new SCA tools focus on providing continuous visibility into third-party software libraries within customers’ repositories and protecting the software supply chain. The solution offers several unique and differentiating features that enhance its effectiveness in managing third-party code vulnerabilities:

  • Continuous Visibility and Tracking: Lacework SCA provides continuous visibility into third-party software libraries used in customer repositories. This includes direct and indirect dependencies, offering a comprehensive view of the software supply chain.
  • Detailed Vulnerability Insights: Beyond basic SCA functionalities, Lacework delves into specific details like where vulnerable functions are used in the code, the frequency of their use, and identifying responsible parties for introducing and fixing vulnerabilities.
  • Real-time Software Bill of Materials (SBOMs): Lacework maintains an always up-to-date SBOM for every application. This feature is essential for understanding the components that make up software applications and managing associated security risks.
  • Extended to Cloud-Native Workloads: Lacework extends its SCA capabilities to include visibility of vulnerable packages throughout their lifecycle, from their usage in source code to their activity in cloud-native workloads. This holistic view is crucial for comprehensive security management.
  • Active Vulnerability Detection (AVD): The integration of AVD with the Lacework runtime agent, known as the Code Aware Agent (CAA), allows for identifying runtime package activity across various cloud workloads. This feature enhances the detection and management of vulnerabilities in real time.
  • Prioritization Based on Actual Use: Lacework’s SCA allows organizations to prioritize updates or removal of packages based on their actual activity. This approach helps efficiently allocate resources to address the most critical vulnerabilities first.
  • Understanding Open-Source License Risks: Along with security vulnerabilities, Lacework SCA also provides insights into open-source license risks, a crucial aspect of compliance and risk management in software development.
  • Combining Static and Runtime Analysis: The unique approach of combining static program analysis with runtime insights offers a more dynamic and effective method of detecting and managing vulnerabilities in software applications.

These features make Lacework’s SCA a powerful tool for enterprises, providing a deeper and more actionable understanding of third-party code vulnerabilities, thereby enhancing their software applications’ overall security posture and compliance.

The new SCA capabilities will help organizations maintain an up-to-date software bill of materials (SBOMs) for every application and provide continual visibility into their software supply chain, including understanding open-source license risks.

Static Application Security Testing

Lacework’s SAST capabilities provide visibility into complex vulnerabilities in internet-facing applications and include a sophisticated analysis of call chains and control paths to identify potential security risks with low false positives and negatives.

The new SAST tool has several unique and differentiating features that set it apart from traditional SAST solutions:

  • Sophisticated Analysis Techniques: Lacework SAST utilizes advanced methods to analyze an application’s call chains and control paths. This deep analysis helps in understanding the context of the code, leading to more accurate identification of potential security vulnerabilities.
  • Low Rate of False Positives and Negatives: A common issue with traditional SAST tools is the high rate of false positives and false negatives. Lacework’s SAST is designed to minimize both, providing more precise and reliable results.
  • Integration of Compensating Controls Recognition: The tool can recognize when developers have implemented compensating controls in the code to mitigate risks. This feature ensures that the security analysis is more aligned with the actual security posture of the application.
  • Customization and Configurability: Lacework allows security engineers to customize and add rules tailored to the specific needs of their unique codebase. This level of configurability ensures that the tool can adapt to a wide range of applications and security requirements.
  • Speed and Scalability: Lacework SAST is designed to be fast and scalable, capable of assessing millions of lines of code in minutes. This feature is particularly beneficial for large-scale enterprise applications and rapid development environments.
  • Comprehensive Visibility into Vulnerabilities: Lacework SAST provides in-depth insights into potential vulnerabilities, especially in internet-facing applications. It tracks the path of untrusted data to identify zero-day vulnerabilities that could lead to serious exploits like SQL injection.
  • Enhanced Security Posture: By integrating sophisticated analysis and precise results, Lacework’s SAST tool improves the overall security posture of applications, enabling security teams to address vulnerabilities more effectively.

These features work together to make Lacework’s SAST a robust and efficient tool for modern application security, helping organizations to secure their first-party code with higher accuracy and less operational overhead.

Analyst’s Take

The new code protection tools extend Lacework’s platform to cover the complete application lifecycle, enhancing its capabilities in code and cloud security. This enables enterprises to innovate and deliver secure cloud-native applications more effectively.

Lacework isn’t alone in delivering tools to protect he entire application lifecycle. It’s a crowded market with solutions from Snopsys, Rapid7, Snyk, and GitLab, among many others. The competitiveness of this market highlights the critical importance of protecting the entire application lifecycle.

The newly introduced features provide Lacework customers with comprehensive visibility throughout the application development process, helping to identify and address security issues before deployment. By integrating code security into its platform,

Lacework unifies code and cloud security, allowing enterprises to develop and deliver secure cloud-native applications more efficiently. The ability to provide integrated cloud and application lifecycle protection is a significant differentiator for Lacework. We like the approach.

Disclosure: Steve McDowell is an industry analyst, and NAND Research an industry analyst firm, that engages in, or has engaged in, research, analysis, and advisory services with many technology companies, which may include those mentioned in this article. Mr. McDowell does not hold any equity positions with any company mentioned in this article.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

Going Eco Benefits Planet And This Hotel’s Bottom Line

Innovation May 29, 2025

What IBM’s Deal For HashiCorp Means For The Cloud Infra Battle

Innovation April 25, 2024

Is Telepathy Possible? Perhaps, Due To New Technology

Innovation April 24, 2024

Luminar Launches Production For Volvo, Shows Next-Gen Halo Lidar

Innovation April 23, 2024

Turning Customers Into Investors – Tiny Health’s Experience

Innovation April 22, 2024

Netflix’s Best New Original Series Is Stressing Me Out

Innovation April 21, 2024
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Why Conversational Commerce is the Future of Shopping

May 29, 2025

10 Leadership Myths You Need to Stop Believing

May 29, 2025

Tesla’s Layoffs Won’t Solve Its Growing Pains

May 29, 2025

Going Eco Benefits Planet And This Hotel’s Bottom Line

May 29, 2025

What IBM’s Deal For HashiCorp Means For The Cloud Infra Battle

April 25, 2024

Latest Posts

The Future of Football Comes Down to These Two Words, Says This CEO

April 25, 2024

This Side Hustle Is Helping Land-Owners Earn Up to $60,000 a Year

April 25, 2024

A Wave of AI Tools Is Set to Transform Work Meetings

April 25, 2024

Is Telepathy Possible? Perhaps, Due To New Technology

April 24, 2024

How to Control the Way People Think About You

April 24, 2024
Advertisement
Demo

InDirectica is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2025 InDirectica. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.