Checkmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)
N/A
PagerDuty
Score 8.6 out of 10
N/A
PagerDuty, Inc. (NYSE:PD) provides digital operations management. Serving organizations of all sizes, PagerDuty aims to help them deliver a perfect digital experience to their customers, every time.
If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
It's the most effective when you need to alert someone specifically or a team. It sends notifications everywhere, like email, phone, and SMS, ensuring critical issues are never missed. The feature, like the event orchestrator, allows us to set logic-based rules that automatically suppress non-emergency alerts.
Their API based customizations which I leveraged to create an ASPM package, which is developer friendly and can extend above the dashboard features, other ones are UI which is great and feels clutter free. Menu and navigation is also good so as support. Only drawback is sometimes scan takes longer which I feel so can be reduced
The UI is more complex than I would like. Part of the challenge is that most users use PagerDuty infrequently; I don't remember how I changed a policy last time. Another part of the challenge is that some users expect alerting to be a trivial feature, and are reluctant to invest any time in reading the documentation.
PagerDuty is reliable and easy to set up. It gives an effective way to notify the team about critical incidents which results in a faster turnaround time on issues. users can customize their alerts rules based on their preferences. Overall it's effective and easy to use which adds great business value.
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
I have not use the 2 technologies for as long as I have used PagerDuty but in my opinion PagerDuty makes things a lot easier. The other tools got the job done and got alerts out but PagerDuty just seemed to make the setup for on-call alert schedules and integrations easier than the others. This isn't to say the others are difficult, just that PagerDuty was slightly better. I also have noticed that more tools have options to integrate to PagerDuty over the other tools.