Revolutionizing Software Supply Chain Security: OX Active ASPM and HCL AppScan in Action

HCL Webinar Linkedin Event Image (LinkedIn Single Image Ad)

In this joint OX Security and HCL Software webinar, hosted by HCL AppScan’s Adam Cave with Michael Smith (HCL Software) and Boaz Barzel (OX Security), the teams introduce HCL AppScan Supply Chain Security: AppScan’s scanning combined with OX Active ASPM. They explain how software supply chain security differs from traditional AppSec by covering the whole pipeline and adding integrity and traceability, why the two companies partnered, and what is driving demand, from Solar Winds-class attacks to tool sprawl. A two-part live demo shows scanning an application with AppScan on Cloud (DAST and SAST) and then correlating, prioritizing, and mapping the results to OSC&R inside OX, with automated response workflows, all set up through a simple API-key integration.

Key Takeaways

  • Supply chain security is broader than traditional AppSec, and adds integrity. Beyond scanning code and running apps, it covers the whole pipeline and validates integrity and traceability from code to cloud and back.
  • OX and HCL AppScan combine world-class scanning with correlation. AppScan brings strong SAST, DAST, SCA, and API scanning; OX correlates across all major AppSec tools and the full pipeline via its pipeline bill of materials.
  • The real drivers are breaches, cost, compliance, and tool sprawl. Solar Winds-class attacks, breach costs, audit gaps, noise, and managing seven or eight separate tools push teams toward consolidated supply-chain security.
  • Developers now influence tool choice, so visibility and fit matter. A handful of security analysts support thousands of developers, so arming them with evidence and visibility is the uphill battle security teams face.
  • The integration is simple and cuts manual triage. Connect AppScan on Cloud with an API key and secret; OX ingests the results, correlates and prioritizes them, maps issues to OSC&R, and reduces noise by roughly 27% or more.
  • It covers discovery, analysis, and response in one flow. OX prioritizes reachable, exploitable, high-impact issues with evidence and DAST remediation guidance, then automates response through no-code workflows like Slack and Jira.

Video Transcript

Speakers

Adam Cave

Product Marketing Manager, HCL AppScan (host)

Product marketing manager for HCL AppScan and the session’s host.

Michael Smith

Michael Smith

View on LinkedIn

Director of Technical Sales, AppScan (HCL Software)

Director of technical sales for AppScan, with nearly 20 years in application security across IBM, HCL, and the commercial space.

boaz li image

Boaz Barzel

View on LinkedIn

Product Enablement, OX Security

Leads product enablement at OX Security, with over a decade of prior experience at Check Point.

FAQ

Traditional AppSec focuses on source code, open-source components, and running applications. Supply chain security looks at the entire pipeline holistically and adds integrity and traceability, validating every piece from code to cloud and back.

To combine AppScan’s world-class scanning (SAST, DAST, SCA, API, container, IaC) with OX’s ability to correlate across all major AppSec tools and the full pipeline (the pipeline bill of materials). HCL can now resell OX Security on HCL paper.

Major attacks such as NotPetya and Solar Winds, the cost of breaches, compliance and audit gaps, alert noise, and tool sprawl, organizations managing seven or eight separate AppSec tools.

HCL AppScan combined with OX Active ASPM: scan with AppScan (or other tools), then integrate into OX for full pipeline visibility, correlation, de-duplication, and prioritization, delivered as a single platform.

Generate an API key and secret in AppScan on Cloud and connect it on the OX connectors page. OX ingests the results into its AppSec data fabric, correlates and prioritizes them, maps issues to OSC&R, and cuts noise by roughly 27% or more.

Both. Full code-to-cloud visibility plus prioritized, evidence-backed triage and automated response via no-code workflows (Slack, Jira). On-prem AppScan Standard or Enterprise can work too, as long as results reach AppScan on Cloud.