Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Feature

Standard

Enterprise

Enterprise +

Automated Threat Modeling

(tick)

(tick)

(tick)

Threat Modeling Profiles

Expand
titleMore info

Threat modeling engine uses profiles to build contextualized attack tree and threat model.

5

15

customized

Issues Tracking

Expand
titleMore info

Repo of security weakness found in threat modeling.

(tick)

(tick)

(tick)

AppSec Knowledge Base

Expand
titleMore info

Developers get real-time help to understand the security issues and how to remediate them with the knowledge base (KB) embedded in the threat modeling sessions. KB is based on CWE and OWASP.

(tick)

(tick)

(tick)

Jira Single-Sign-On

Expand
titleMore info

Users log into CyberSage with their Jira accounts. Seamlessly integrates security threat modeling into the development workflow.

(tick)

(tick)

Issues management Management in Jira

Expand
titleMore info

Developers manages manage the life-cycle security tasks using their Jira development workflow.

(tick)

(tick)

Release management dashboard Management Dashboard

Expand
titleMore info

Supports Support risk-based software release management and CI/CD pipeline.

(tick)

(tick)

ChatGpt integration Integration

Expand
titleMore info

Support developers with security expertise by integrating with OpenAI ChatGPT. Need customer’s ChatGPT API account.

(tick)

(tick)

Issues security risk rating Security Risk Rating

Expand
titleMore info

Prioritize remediation of security weaknessweaknesses. Risk rating considers both likelihood and impact to business.

Basic

Advanced

Advanced

Risk and control repository Control Repository & certification Certification

Expand
titleMore info

Threat modeling engine uses risk and control facts to produce the accurate threat model. Security professionals certifies certify these facts to be accurate so these facts are re-used in all threat modeling sessions to produce accurate results.

(tick)

(tick)

Application inherent risk info Inherent Risk Info Repo

Expand
titleMore info

Enterprise’s Applications Repository for enterprise applications catalog along with their essential inherent risk info. Can be synchronized with the enterprise’s book of record.

(tick)

(tick)

Create threat modeling policiesThreat Modeling Policies

Expand
titleMore info

Configure threat modeling profiles for applications when application applications and business features change. (Configuration is done with out-of-box profiles set.)

(tick)

Risk and impact analysis Impact Analysis

Expand
titleMore info

Analyze risks to applications and their business features, establishes establish impacts to business impact and impact ratingratings.

(tick)

Report Reports and charts Charts

Expand
titleMore info

Graphic reports and charts for real-time security risk status and trends.

(tick)

...