Ideagen's Enterprise Risk Management (ERM) software solution (formerly known as Pentana Risk) fully integrates risk management processes, from identifying and assessing risk business-wide, to assigning and monitoring mitigation plans, all the way through to reporting and defining a long-term strategy for enhanced performance.
N/A
Fortify by OpenText
Score9 out of 10
N/A
An AppSec solution formerly from Micro Focus, spanning SCA, SAST and DAST that supports the breadth and management of any application portfolio, used to secure code. Features API discovery and testing for any application, throughout the software lifecycle.
Pentana is great for monitoring PIs and risks. We find it less helpful for monitoring projects (with the Actions module); it isn't quite flexible enough for our needs, though the support team have been very helpful in adding custom fields for us.
It is best suited for runtime application security scanning and very useful for automation. You can seemlessly integrate with pipeline for dynamic scans. Cloud based apps can also be scanned for vulnerabilities, cross site scripting attacks. Basically all OWASP TOP 10. It is less appropriate to use if you have serverless architecture
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Pentana is excellent for monitoring, recording and reporting on PIs. Very easy to use the PI module.
Pentana is excellent for monitoring risks at various levels (service, strategic etc.). Risks are displayed very clearly in a tree structure and the module is relatively easy to use.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Pentana could improve the free Documents module that comes with Pentana Risk. At the moment documents have to be linked to an action in order to display query results (such as how many documents are due for review) - this can be confusing for users who don't understand why there is an action linked. There is also no easy way for users to see the documents that are assigned to them.
We would like to use the Actions module fully in order to monitor our corporate projects, but it a bit confusing for users and not very flexible when a project doesn't mirror Pentana's way of monitoring actions.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Since every firm needs to perform static code analysis on their applications, I believe Micro Focus Fortify WebInspect would work well for them (they also offer dynamic scanning, although I haven't used it myself). Different static analysis tools scan code in different ways, and Micro Focus Fortify WebInspect asks you to submit a complete build of the application along with debugging files. Depending on how your company builds its apps, this requirement may be simple or challenging.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Some modules are more user-friendly than others. It's sometimes not obvious where to click to update the fields (or even that field titles can be clicked on). We have written 'Howdys' to help users. There can also seem to be a lot of steps/clicks to updating risks and actions. The Reports module on Pentana classic is certainly not user-friendly, particularly the Report Layout and Charts modules - we were told these would be integrated into the web version but this hasn't happened yet.
It is a cloud-based platform which can provide us a very useful and unique features like Application Assessment, Scans, Vulnerability Test, Comprehensive Reporting, Monitoring, etc. Fortify by Open Text is also outstanding in various parameters for the support and integration and it is highly adaptable in various DevOps Program where you need secure app testing with all given features.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We selected Pentana because our neighbouring authorities are users and had spoken highly of the product and given us demonstrations; some of our staff were also familiar with Pentana when it was called Covalent. It seemed to be the best product on the market for monitoring risks, PIs and projects.
Fortify Application Defender is a little more timely and upfront with a lot of their information on cyber security. we like what they provide and how they communicate with our users. I think they have a good understanding and practice in their field. they seem best suited for us and the best fit.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Pentana Risk has allowed my team to focus on other areas of work whereas before we would be manually chasing for updates on PIs and risk. Pentana Risk does the chasing for us!
We are able to produce reports for audit purposes very easily, rather than sending spreadsheets which is what we used to do.
New managers can easily inherit risks, projects and PIs and see all of this on a custom portal, saving them time when they start.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info