TechValidate Research on Klocwork


Klocwork Case Study

Siae Microelettronica Spa

Introduction

This case study of SIAE MICROELETTRONICA SPA is based on a March 2021 survey of Klocwork customers by TechValidate, a 3rd-party research service.

Klocwork provides us with great ease of configuration and issue management across the team."

“Working with certified tools increases trust in the tool execution results.”

Challenges

Tools evaluated or used prior to selecting Perforce SAST Tools:

  • SonarSource/SonarQube

Industry Feedback

For static code analysis tools, key features include:

  • The ease of setting up and running static code analysis: agree
  • Integration into CI/CD systems: strongly agree
  • Differential analysis for speed and efficiency: strongly agree
  • The ability to support huge codebases: strongly agree
  • Support for all coding languages that we use: agree
  • No need to pre-process code prior to scanning: agree

Importance of the following:

  • Have a consistent pricing model from your Static Application Security Testing (SAST) tool vendor: important
  • Have a SAST tool that can be executed via flexible deployment options (Desktop/IDE/CI/Cloud/Containers): very Important
  • Have customizable quality reports and analysis: very Important
  • Get accurate and clean of noise reports: critical

Said that audit and/or stakeholder-ready scan results help to speed up release cycles and time to market somewhat faster.

They are not comfortable with sharing and uploading their source code to an SAST tool vendor cloud.

Security and safety coding standards coverage most important for them:

  • CERT

Enterprise console and reporting framework capabilities they value the most:

  • Compliance and security reports
  • Prioritize defects based on severity, location, and lifecycle
  • Distinguish new issues from legacy code issues

Results

Klocwork compared to other tools that used or evaluated:

  • Ability to scale to projects of any size: superior
  • Wide range of developer tools: superior
  • Continuous compliance: best-in-class
  • Ease of automation: superior
  • Differential analysis: better
  • Flexible deployment options: superior




About This Data

This data was sourced directly from verified users of Klocwork by TechValidate.

TechValidate verifies the identity and organizational affiliation of all participants that contribute to published research data. When research participants so desire, we also guarantee their anonymity so that they may share information honestly and freely.


More Research on Klocwork