Application Security, Inc. Announces Alliance with Internet Security Systems to Provide Best-in-Class Database Security Solutions

GARTNER IT Security Summit, Washington, D.C. — June 6, 2005 — Application Security, Inc. (AppSecInc) (, the leading provider of proactive database security solutions for the enterprise, today announced a strategic relationship with Internet Security Systems (ISS) that highlights the advantages of a layered approach to securing enterprises. The company made the announcement from the Gartner IT Security Summit 2005 being held at the Marriott Wardman Park Hotel in Washington, DC from June 6 through 8.

“The front line in the information security battle isn’t just moving toward applications and databases, it’s already there,” said Jack Hembrough, president and chief executive officer of Application Security, Inc. “AppSecInc and Internet Security Systems fully understand that, and are helping to provide organizations around the world with the solutions needed to defend the integrity of their information resources proactively and cost effectively — regardless of where threats originate.”

Under terms of the ISS and AppSecInc agreement, the companies will engage in joint sales and marketing efforts in support of the AppDetective(TM) database vulnerability assessment scanner. With more than 300 customers worldwide, AppDetective is AppSecInc’s flagship product, and the market share leader in its category.

Gartner Research Director Rich Mogull states in his report on effective data security, “The principal goal of most attacks, whether from external sources or internal malicious behavior, is to compromise data. Now is the time for enterprises to protect information assets as thoroughly as they protect their walls and doors.”(1)

“For the last decade, Internet Security Systems has been committed to offering enterprise organizations solutions that preemptively protect them from the full range of Internet Threats,” said Greg Adams, vice president of product management for Internet Security Systems. “AppDetective is the centerpiece of what leading analysts call “the most comprehensive database security solution.’ We are pleased to make it available to current ISS customers.”

Foundation for the Industry’s Most Complete Security Solution for the Application Tier

AppDetective is the foundation for the industry’s most complete solution for the application tier — the only in the industry which applies to corporate applications, the complete vulnerability management methodology enterprises already use to secure their networks and general-purpose operating systems. AppDetective discovers applications within an organization’s infrastructure and assesses their security strength. Backed by a proven security methodology and extensive knowledge of application-level vulnerabilities, AppDetective locates, examines, reports and fixes security holes and misconfigurations. As a result, enterprises can proactively harden their database applications — the crown jewels at most any organization — by eliminating vulnerabilities.

AppRadar(TM) complements AppDetective by providing real-time protection and security auditing. As a result, customers maintain protection even against new threats, insider threats, or known threats against databases scheduled for patching. DbEncrypt(TM) provides a last line of defense by transparently encrypting selected database columns, securing data even if the database is compromised.

About Application Security, Inc. (AppSecInc)

AppSecInc is the leading provider of application security solutions for the enterprise. AppSecInc products proactively secure enterprise applications at more than 300 organizations around the world. The industry’s most complete line of security solutions for the application tier, AppSecInc products apply to applications the same vulnerability management methodology organizations use to secure their networks and general-purpose operating systems. By securing data at its source, AppSecInc solutions enable organizations to more confidently extend their business with customers, partners and suppliers. Please contact us at 1-866-927-7732 to learn more, or visit us on the web at

About Gartner IT Security Conference

Gartner IT Security Summit hits the critical spot between strategic planning and tactical advice. Gartner analysts, industry experts and IT security practitioners will deliver unbiased, realistic analysis on the current state of IT security, as well as an independent overview of the market over the next 12-18 months. For more information, please visit

Don't miss