The typical implementation process for Checkmarx One involves several key steps to ensure a smooth integration into your development and security workflows. Here’s a detailed overview:
Initial Assessment and Planning: This phase involves understanding the specific needs and requirements of your organization. It includes assessing the current state of your application security program and defining the scope of the implementation.
Environment Setup: Setting up the necessary infrastructure, which may include cloud or on-premises environments, depending on your organization's preferences. This step ensures that all prerequisites are in place for a successful deployment.
Installation and Configuration: Installing the Checkmarx One platform and configuring it according to your organization's security policies and development workflows. This includes setting up integrations with CI/CD pipelines, version control systems, and other development tools.
Integration with Development Tools: Integrating Checkmarx One with your existing development tools such as IDEs, GitHub, GitLab, Jenkins, and others. This step ensures that security scans can be seamlessly incorporated into the development process.
Customizing Security Policies: Defining and customizing security policies to match your organization's specific requirements. This includes setting up rules for SAST, SCA, DAST, and IaC security scans.
Training and Onboarding: Providing training sessions for developers and security teams to ensure they are familiar with the platform's features and how to use them effectively. This step is crucial for maximizing the benefits of the platform.
Initial Scans and Baseline Assessment: Running initial security scans to establish a baseline of the current security posture. This helps in identifying existing vulnerabilities and setting priorities for remediation.
Ongoing Monitoring and Optimization: Continuously monitoring the platform's performance and making necessary adjustments to optimize its effectiveness. This includes regular updates and maintenance to ensure the platform remains up-to-date with the latest security threats.
Implementation Duration:
The duration of the implementation process can vary depending on the size and complexity of the organization. Typically, it can take anywhere from a few weeks to a few months to fully implement Checkmarx One. Factors influencing the timeline include the number of applications to be scanned, the complexity of the development environment, and the level of customization required
Checkmarx One can be customized to fit specific business needs. Here are some key customization options:
Custom Security Policies: You can define and manage custom security policies tailored to your organization's requirements. This includes setting specific rules for open-source packages, vulnerabilities, and licenses.
Custom Queries: The AI Query Builder allows you to write and fine-tune custom SAST queries, enabling you to address unique security concerns specific to your codebase.
Integration with Development Tools: Checkmarx One integrates seamlessly with various development tools and CI/CD pipelines, allowing you to customize the integration to fit your existing workflows.
Customizable Dashboards and Reports: The platform provides customizable dashboards and reports, enabling you to track and visualize security metrics that are most relevant to your organization.
Role-Based Access Control: You can customize user roles and permissions to ensure that only authorized personnel have access to specific features and data.
The total cost of ownership for Checkmarx One includes several components beyond the basic licensing fee:
Setup Fees: Initial setup fees may apply, depending on the complexity of your environment and the level of customization required.
Maintenance and Upgrades: Ongoing maintenance and upgrades are typically included in the subscription cost, but it's important to confirm this with the Checkmarx sales team.
Support Charges: Checkmarx offers different levels of support, including standard and premium support options. Premium support may come with additional charges, providing prioritized technical assistance and operational support.
Training and Onboarding: Training sessions for developers and security teams may incur additional costs, especially if you require extensive or customized training programs.
Customization Costs: Customizing the platform to fit specific business needs, such as creating custom queries or integrating with unique development tools, may involve additional costs.
Checkmarx One offers a comprehensive range of training and support options to help new users get started and make the most of the platform:
Documentation and User Guides: Extensive documentation and user guides are available, covering everything from initial setup to advanced features.
Interactive Courses: Through Checkmarx Codebashing, users can access interactive courses that demonstrate security vulnerabilities, their impact, and remediation techniques.
Webinars and Online Tutorials: Checkmarx provides webinars and online tutorials to help users understand and utilize the platform effectively.
Customer Support: Checkmarx offers various levels of customer support, including standard and premium options, providing technical assistance and operational support.
Community Forums: Users can participate in community forums to ask questions, share experiences, and get advice from other users and Checkmarx experts.
Onboarding Sessions: Personalized onboarding sessions are available to help new users integrate Checkmarx One into their development workflows.
Checkmarx One implements several robust security measures to protect data:
Data Encryption: Data is encrypted both in transit and at rest to ensure its confidentiality and integrity.
Access Controls: Role-based access control (RBAC) is used to restrict access to sensitive data and functionalities based on user roles and permissions.
Audit Logging: Comprehensive audit logs are maintained to track access and changes to data, providing a trail for security investigations.
Compliance with Security Standards: Checkmarx adheres to industry-standard security practices and compliance requirements, such as SOC 2, GDPR, and HIPAA.
Regular Security Updates: The platform is regularly updated with security patches and enhancements to address emerging threats and vulnerabilities.
Data Masking: Sensitive data can be masked to prevent unauthorized access and exposure.
Network Security: Measures such as firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) are in place to protect the network infrastructure.
Incident Response: Checkmarx has a robust incident response plan to quickly detect, respond to, and mitigate security incidents.
These measures help ensure that data within Checkmarx One is protected against unauthorized access, breaches, and other security threats.
Checkmarx One releases updates regularly to ensure the platform remains up-to-date with the latest security features and improvements. Here are some key points about their update process:
Regular Updates: Checkmarx One typically releases updates on a quarterly basis, including new features, enhancements, and security patches.
Major Releases: Major updates that introduce significant new features or architectural changes are usually released annually.
Patch Releases: Smaller patches and hotfixes are released as needed to address critical issues or vulnerabilities.
Automatic Updates: For cloud-based deployments, updates are often applied automatically, minimizing disruption to users.
Notification System: Users are notified of upcoming updates and new releases through the Checkmarx Support Portal and email notifications.
Documentation: Detailed release notes and documentation are provided with each update, outlining the changes and new features.
Checkmarx One has clear policies regarding data ownership and portability to ensure that customers retain control over their data:
Data Ownership: Customers retain full ownership of their data. Checkmarx does not claim any ownership rights over the data processed by the platform.
Data Portability: Checkmarx One supports data portability, allowing customers to export their data in standard formats. This ensures that customers can move their data to other systems if needed.
Data Access: Customers have the right to access their data at any time. This includes the ability to view, download, and manage their data through the platform.
Data Deletion: Upon request, Checkmarx will delete customer data in accordance with their data retention policies and applicable regulations.
Compliance: Checkmarx complies with relevant data protection regulations, such as GDPR, ensuring that customer data is handled securely and in compliance with legal requirements.
These policies help ensure that customers have control over their data and can manage it according to their business needs.
Checkmarx One offers flexible terms for scaling up or down to accommodate changing organizational needs:
Flexible Licensing: Checkmarx provides flexible licensing options that allow organizations to adjust their subscription based on their current requirements. This includes the ability to add or remove licenses as needed.
Modular Approach: The platform's modular design enables organizations to scale specific components, such as SAST, SCA, or API security, independently based on their evolving security needs.
Usage-Based Pricing: Checkmarx offers usage-based pricing models, allowing organizations to pay for what they use. This is particularly beneficial for organizations with fluctuating security testing needs.
Support for Multiple Environments: Checkmarx One supports both cloud and on-premises deployments, providing flexibility to scale across different environments.
The terms and conditions for contract renewal and cancellation for Checkmarx One are as follows:
Contract Renewal: Contracts are typically renewed on an annual basis. Customers are notified in advance of the renewal date and provided with the option to renew or modify their subscription.
Cancellation Policy: Customers can cancel their subscription by providing written notice to Checkmarx. The notice period and any applicable cancellation fees are specified in the contract.
Refund Policy: Refunds for unused portions of the subscription are generally not provided unless specified in the contract. It's important to review the specific terms outlined in the agreement.
Termination for Cause: Either party may terminate the contract for cause if the other party breaches any material term of the agreement and fails to remedy the breach within a specified period.
Checkmarx One meets several industry-standard compliance requirements to ensure data security and privacy:
SOC 2: Checkmarx One is SOC 2 compliant, ensuring that it meets rigorous standards for security, availability, and confidentiality.
GDPR: The platform complies with the General Data Protection Regulation (GDPR), ensuring the protection of personal data for EU customers.
HIPAA: Checkmarx One meets the requirements of the Health Insurance Portability and Accountability Act (HIPAA), making it suitable for use in healthcare environments.
ISO 27001: The platform is certified under ISO 27001, demonstrating its commitment to information security management.
PCI DSS: Checkmarx One adheres to the Payment Card Industry Data Security Standard (PCI DSS), ensuring secure handling of payment card information.
Checkmarx One
By Checkmarx Ltd