Organizations face several choices when starting or maturing an application security program. Few organizations have the budgets and internal capabilities to do more than one or two of these at a time.
As teams look at their choices for improving software security, there is no shortage of software security categories to choose from. During the development process, Static Application Security Testing (SAST) and Interactive Application Security Testing (IAST) promise to identify coding errors that can result in vulnerabilities.
Later in the life cycle, Dynamic Application Security Testing (DAST) tests running applications to identify issues.