Cigital Explained

Cigital
Type:Public
Foundation:1992, as Reliable Software Technologies, renamed in 2000 to Cigital[1]
Location City:Dulles, VA
Location Country:U. S.
Location:Mountain View, CA
Locations:Atlanta, Bangalore, Bloomington, Boston, Chicago, Dallas, Minneapolis, New York, Santa Clara, Seattle, London
Area Served:Worldwide
Key People:Gary McGraw
Industry:software security
Services:Architecture Analysis, Ethical Hacking, Penetration Testing, Static Analysis, Training, Policy Development
Owner:Public Company
Parent:Synopsys
Num Employees:400 security consultants[2]
Homepage:https://www.synopsys.com/software-integrity.html
Fate:acquired by Synopsys

Cigital was a software security managed services firm based in Dulles, VA.[3] The services they offered included application security testing, penetration testing, and architecture analysis. Cigital also provided instructor-led security training and products such as SecureAssist, a static analysis tool that acts as an application security spellchecker for developers.[4] [5] [6] [7] [8]

History

Cigital was established in 1992 with grants from DARPA.[9] [10] In 1999 the firm created ITS4, which according to Cigital, was the world's first static analysis tool.[11] The technology in this product was eventually licensed to Kleiner Perkins and used as the basis for the creation of Fortify Software in 2003. In 2010, Fortify was acquired by Hewlett Packard for $300 million.[12]

BSIMM (Build Security In Maturity Model)[13] is a software security measurement framework that helps organizations compare their software security to other organizations.[14] BSIMM was started as a joint project by Cigital and Fortify Software.[15] [16]

In 2002, Cigital announced finding a vulnerability in Visual C++ .Net compiler[17] [18] [19] (related to a GS compiler flag being inefficient).[20] Cigital was criticized for not following responsible disclosure in this case, however, Cigital has defended its position due to the nature of the vulnerability.

On November 30, 2016, Cigital was acquired by Synopsys, an electronic design automation company.[21]

Acquisitions

In November 2014, Cigital acquired IViz Security, an information security company in the field of on-demand application penetration testing.

In November 2016, it was announced that Synopsys, Inc. would be acquiring Cigital and Codiscope.[22]

References

  1. http://www.hoovers.com/company/Cigital_Inc/rthtthi-1-1njdap.html Cigital Inc. profile
  2. Web site: The Cigital Story. Cigital. May 27, 2016. May 2016. https://web.archive.org/web/20160803230231/https://www.cigital.com/about/our-story/. August 3, 2016. dead.
  3. News: Schafer . Cigital Helps Wired World Stay That Way; Dulles Firm Works to Minimize Its Clients' Risks of Software Failure . . January 25, 2001 . Sarah.
  4. Web site: Home . cigital.com.
  5. News: Johnston . Cigital Sees Secure Opportunities; Already Profitable, the 10-Year- Old Software Maker Is Poised to Grow . . August 26, 2002 . Nicholas .
  6. News: Overly . The Download: Dulles-Based Cigital Secures $50M from Private Equity Firm LR Partners (Posted 2013-10-07 15:56:28); Software Security Firm Brings in Private Equity Shop to Expand in Existing Markets, Reach New Ones. . October 7, 2013 . Steven .
  7. News: King . Town, gown and techies team up in Bloomington. . October 7, 2013 . Mason .
  8. News: Smeltz . Hackers Who Attack U.S. in Line for Lucrative Payoffs. . October 27, 2012 . October 7, 2013 . Adam .
  9. Web site: Calnan. Christopher. Praetorian pours profits into new products. 28 June 2013.
  10. Web site: Reliable Software Technologies Corp.. SBIRSource. 29 July 2013.
  11. Web site: ITS4: Software Security Tool. 21 April 2015. https://web.archive.org/web/20150421051420/http://www.cigital.com/its4/. 21 April 2015. dead.
  12. Web site: Rao. Leena. HP Acquires Software Security Company Fortify. 17 August 2010 . Tech Crunch.
  13. Web site: Building Security In Maturity Model BSIMM. www.bsimm.com. en. 2019-08-29.
  14. Web site: McGraw. Gary. Software [In]security: The Building Security In Maturity Model (BSIMM)]. InformIT. 28 June 2013. rian Chess . Sammy Migues . March 16, 2009.
  15. https://archive.today/20120918135442/http://www.wallstreetandtech.com/articles/216403548 The Rocky Road To More Secure Code, Wall Street and Technology
  16. https://blogs.wsj.com/digits/2009/03/04/new-effort-hopes-to-improve-software-security/ New Effort Hopes to Improve Software Security, Wall Street Journal
  17. https://www.wsj.com/articles/SB101364296255025200 Microsoft's New 'Compiler' Program Has Security Flaw, Consultancy Says. WSJ
  18. http://news.cnet.com/2100-1001-837428.html Flaw spotted in new Microsoft tool. CNet
  19. News: Net Security Company Reports Flaw. . February 15, 2002 .
  20. http://news.cnet.com/2100-1001-838096.html Was Cigital security warning too hasty? CNet
  21. News: Synopsys Completes Acquisitions of Cigital and Codiscope. 2018-10-29. en.
  22. Web site: Synopsys (SNPS) to Acquire Cigital and Codiscope. StreetInsider.com. 11 November 2016. si.

External links