Cigital was a
software security
Application security (short AppSec) includes all tasks that introduce a secure software development life cycle to development teams. Its final goal is to improve security practices and, through that, to find, fix and preferably prevent security i ...
managed services firm based in
Dulles, VA
Dulles () is an unincorporated area in Loudoun County, Virginia, United States, and is part of the Washington metropolitan area. The headquarters of Northrop Grumman Innovation Systems and ODIN Technologies, as well as the former headquarters of ...
.
The services they offered included
application security
Application security (short AppSec) includes all tasks that introduce a secure software development life cycle to development teams. Its final goal is to improve security practices and, through that, to find, fix and preferably prevent security i ...
testing,
penetration test
A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system; this is not to be confused with a vulnerability assessment. T ...
ing, and
architecture
Architecture is the art and technique of designing and building, as distinguished from the skills associated with construction. It is both the process and the product of sketching, conceiving, planning, designing, and constructing building ...
analysis. Cigital also provided instructor-led security training and products such as SecureAssist, a
static analysis tool that acts as an application security spellchecker for developers.
[
][
]
History
Cigital was established in 1992 with grants from
DARPA
The Defense Advanced Research Projects Agency (DARPA) is a research and development agency of the United States Department of Defense responsible for the development of emerging technologies for use by the military.
Originally known as the Adv ...
. In 1999 the firm created ITS4, which according to Cigital, was the world's first
static analysis tool. The technology in this product was eventually licensed to
Kleiner Perkins
Kleiner Perkins, formerly Kleiner Perkins Caufield & Byers (KPCB), is an American venture capital firm which specializes in investing in incubation, early stage and growth companies. Since its founding in 1972, the firm has backed entrepreneurs ...
and used as the basis for the creation of
Fortify Software in 2003. In 2010, Fortify was acquired by
Hewlett Packard
The Hewlett-Packard Company, commonly shortened to Hewlett-Packard ( ) or HP, was an American multinational information technology company headquartered in Palo Alto, California. HP developed and provided a wide variety of hardware components ...
for $300 million.
BSIMM (Build Security In Maturity Model) is a software security measurement framework that helps organizations compare their software security to other organizations. BSIMM was started as a joint project by Cigital and
Fortify Software.
In 2002, Cigital announced finding a vulnerability in Visual C++ .Net compiler
(related to a GS compiler flag being inefficient).
[Was Cigital security warning too hasty? CNet](_blank)
/ref> Cigital was criticized for not following responsible disclosure in this case, however, Cigital has defended its position due to the nature of the vulnerability.
On November 30, 2016, Cigital was acquired by Synopsys, an electronic design automation company.
Acquisitions
In November 2014, Cigital acquired IViz Security, an information security company in the field of on-demand application penetration testing
A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system; this is not to be confused with a vulnerability assessment. T ...
.
In November 2016, it was announced that Synopsys, Inc. would be acquiring Cigital and Codiscope.[{{cite web, title=Synopsys (SNPS) to Acquire Cigital and Codiscope, url=http://www.streetinsider.com/Corporate+News/Synopsys+(SNPS)+to+Acquire+Cigital+and+Codiscope/12216651.html, website=StreetInsider.com, accessdate=11 November 2016, ref=si]
References
External links
Synopsys Software Integrity Website
Software companies based in Virginia
Companies based in Dulles, Virginia
Defunct software companies of the United States
2016 mergers and acquisitions