BookmarkSubscribeRSS Feed
gra_in_aus
Quartz | Level 8

Hi,

 

Currently reviewing Open Source and Enterprise toolsets for SAST.  I noted that on a SAS White Paper (https://www.sas.com/content/dam/SAS/en_us/doc/whitepaper1/sas-software-security-framework-107607.pdf) that SAS uses various Security Frameworks using Open Source and Enterprise toolsets.  I would like to know which ones are utilised by SAS, as would like to assess their capabilities for the SAST Software review that I am doing to cover off the SAS Grid Platform and Redshift Clusters that we utilise for our analytics and data warehouse.

 

Many thanks

 

G

5 REPLIES 5
LinusH
Tourmaline | Level 20

I don't think this is general knowledge.

If you wish to have insight in SAS Institute processes, you should you SAS sales represenatative, or a TAM if you've been appointed one.

Data never sleeps
gra_in_aus
Quartz | Level 8
Can't see why there would be a problem disclosing the open-source SAST that is used. How different is SAS announcing that they use cloud academy? or any other vendors advertise that SAS is a customer of theirs?

I just information to see what SAST tools to cover off SAS and Redshift applications created by users of the servers.
SASKiwi
PROC Star

What SAST tools are currently used in your organisation? Your IT Security staff should be able to advise. Why not just follow their guidance? I doubt the SAST tool requirements for your organisation would align withj SAS's so I see limited value in asking them about this.   

gra_in_aus
Quartz | Level 8
Can't see why there would be a problem disclosing the open-source SAST that is used. How different is SAS announcing that they use cloud academy? or any other vendors advertise that SAS is a customer of theirs?

I just information to see what SAST tools to cover off SAS and Redshift applications created by users of the servers.
SASKiwi
PROC Star

If you think SAS can help you on SAST, then by all means contact them via Tech Support or your account manager. In my experience, the Information Security staff I work with are the ones conducting SAST tests and are most familiar with our IT environment so they are the ones I would start out consulting with. 

suga badge.PNGThe SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment. 

Join SUGA 

Discussion stats
  • 5 replies
  • 76754 views
  • 0 likes
  • 3 in conversation