Skip to content

Kaiser Permanente's Game-Changing Tool Shifts App Security to Design Phase

Say goodbye to costly rework. Kaiser Permanente's new tool ensures library security and licensing before selection, boosting efficiency in application development.

To this building there are windows and doors. Pipe is attached to this wall. In-front of this...
To this building there are windows and doors. Pipe is attached to this wall. In-front of this building there are rods.

Kaiser Permanente's Game-Changing Tool Shifts App Security to Design Phase

Kaiser Permanente, a major healthcare provider with 12.2 million customers and 200,000 employees, has made strides in enhancing its application security. At the 2018 Nexus Users' Conference, Xin Xu, an information security principal at Kaiser Permanente, presented a tool that shifts security checks to the early design phase, potentially saving significant rework.

Kaiser Permanente uses Sonatype IQ to manage its component repositories. However, in a typical build process, security checks are performed after selecting a library, which can lead to costly rework. To address this, Kaiser Permanente developed a tool that queries Sonatype IQ at the beginning of the design process. This tool, presented by Xin Xu, ensures library security and licensing before selection, saving time and resources.

The tool, developed by an unidentified Kaiser Permanente security team member, shifts the entire security process to the whiteboard line. It has a simple interface and mimics the Maven process to evaluate libraries and provide relevant details. This innovative approach has been praised for its efficiency and potential to improve application security in large organizations like Kaiser Permanente.

Kaiser Permanente's tool, presented at the 2018 Nexus Users' Conference, demonstrates a significant advancement in application security. By shifting security checks to the early design phase, the tool can save considerable rework and improve overall efficiency. With its large customer base and active application development activity, Kaiser Permanente stands to benefit greatly from this innovative approach to security.

Read also:

Latest