乐鱼(Leyu)体育官网

Industries

Helping clients meet their business challenges begins with an in-depth understanding of the industries in which they work. That鈥檚 why 乐鱼(Leyu)体育官网 LLP established its industry-driven structure. In fact, 乐鱼(Leyu)体育官网 LLP was the first of the Big Four firms to organize itself along the same industry lines as clients.

How We Work

We bring together passionate problem-solvers, innovative technologies, and full-service capabilities to create opportunity with every insight.

Learn more

Careers & Culture

What is culture? Culture is how we do things around here. It is the combination of a predominant mindset, actions (both big and small) that we all commit to every day, and the underlying processes, programs and systems supporting how work gets done.

Learn more

Reducing risk and driving innovation with Microsoft Application Inspector

Tips for effectively managing a software portfolio

Share

Software behavior 鈥� an overlooked risk

Leaders invest in software development to achieve business goals faster. With constant pressure around pushing new features and speed to market, it is difficult for IT organizations to keep tabs on the capabilities and behaviors of the portfolio of software they build. While typical application security testing like static application security testing (SAST) and software composition analysis (SCA) are used to help spot known vulnerabilities and anti-patterns, a necessary part of reducing risk for a business requires a solid knowledge of your applications鈥� features and capabilities.

Targeting the things that matter

The goal of聽聽teams is to protect the business from relevant threats so developers鈥� primary focus can remain on new features that deliver innovation and growth. For any given organization those threats may look and feel a bit different.

For example, some companies鈥� software portfolios may rely heavily on sending and receiving data from external sites, where pre-built patterns around secure input and output handling would increase developer efficiency. Others may have a large prevalence of source code and third-party dependencies related to cryptography, where evangelizing the right hashing algorithms and encryption protocols used across the portfolio reduces significant risk.

But without knowing what鈥檚 happening in an application鈥檚 code base, reducing risk and optimizing one鈥檚 portfolio for the right business outcomes becomes harder because threat prevention, developer education efforts such as聽, and software portfolio strategy become a guessing game.

Reducing business risk with Application Inspector

聽is an open-source tool that identifies a long list of 鈥渋nteresting鈥� features in source code, such as...

  1. What types of interactions the software has with the underlying operating system
  2. Whether the application has any integration with popular social media sites
  3. Whether the application may collect personal user data, triggering the need for聽

Such information can be used to understand which risks pose the greatest threat to the software your organization develops.

乐鱼(Leyu)体育官网 has identified a few moments where Application Inspector can help answer difficult questions:

NumberMomentApplication Inspector can answer questions like...Useful for...
1When you need to understand a single applicationWhat are the main things this application does?Knowing what controls I may need around my application (goes well with an聽)
2When you need to understand a portfolio of applicationsWhat is it that my portfolio of applications does, and how is that changing over time?Planning technology investments and security pattern creation
3When there has been a cyber security breachHas something changed in the functionality of a particular application since the attacker had access to my source code repositories?Protecting users from a malicious actor as part of聽
4When you need to understand what capabilities malware has and you have the source codeWhat does this malware do?Knowing what remediation is needed or preventative controls I may need in the future


Application Inspector is free to use, can be automated in build pipelines for聽聽teams, and updated regularly with new features. Adding Application Inspector to a software management toolset, in combination with traditional application security capabilities like SAST and SCA, may help to more quickly and accurately protect the organization from relevant threats, identify opportunities for feature rationalization across the portfolio, and devote more time to the frequent production of high-quality software.

Microsoft and 乐鱼(Leyu)体育官网 are聽聽and frequently work together to solve the hardest business problems facing large organizations.

This blog article is not intended to address or provide advice concerning the specific circumstances of any particular individual or entity and does not constitute an endorsement of any entity or its products or services.

The 乐鱼(Leyu)体育官网 name and logo are trademarks used under license by the independent member firms of the 乐鱼(Leyu)体育官网 global organization.

Meet the team

Image of Charles A. Jacco
Charles A. Jacco
Principal, Cyber Security, 乐鱼(Leyu)体育官网 US
Image of Caleb Queern
Caleb Queern
Managing Director, Cyber Security, 乐鱼(Leyu)体育官网 US

Explore related insights

Thank you!

Thank you for contacting 乐鱼(Leyu)体育官网.聽We will respond to you as soon as possible.

Contact 乐鱼(Leyu)体育官网

Use this form to submit general inquiries to 乐鱼(Leyu)体育官网. We will respond to you as soon as possible.

By submitting, you agree that 乐鱼(Leyu)体育官网 LLP may process any personal information you provide pursuant to 乐鱼(Leyu)体育官网 LLP\'s .聽

An error occurred. Please contact customer support.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services 乐鱼(Leyu)体育官网 can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the 乐鱼(Leyu)体育官网 International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline