Solutions

Security work starts with a team and a decision.

Choose the workflow that matches what you are responsible for: a code change, an application portfolio, a device release or a firmware update. Each solution explains the inputs, review process and deliverables.

Code Security · and combined product review

Software and application security

Keep source analysis in the delivery workflow and give security teams a usable view across participating repositories.

FDIE

Firmware, devices and technical assessment

Investigate what is inside an image, compare releases and produce evidence for the people who own the product.

Plan the first evaluation

Choose a representative input and a useful result.

Starting points for an evaluation
TeamBringCheck the result with
Application engineeringA known repository and a recent security-relevant changeThe engineers and CI owners who will act on the finding
Enterprise securitySeveral repositories belonging to one serviceThe application owner and the team setting remediation policy
Device engineeringAn authorised firmware image and a related releaseThe product engineers who understand the components and update

Product capabilities, deployment and commercial terms are separate parts of the decision. Review the product pages for analysis scope, the plans for resources and features, and the security centre for data handling.