CodeOne
AMS(AppScan Management System)
What is AMS?
AMS(AppScan Management System)
AMS(AppScan Management System for Dynamic) is a user role-based working tool
that uses HCL AppScan Standard as its scanning engine and provides a web-based UI.
This allows application managers authorized by administrators to perform vulnerability scans directly.

Registered on Public Procurement Service
digital shopping mall

"AMS is a product certified with GS quality Level 1."
Why AMS?
Limitations of Traditional Security Testing
Product Introduction
Product Features
Service
Management
Testing
1. Automated and Integrated Service

Automation Strategy
Expanding application security coverage and
improving application security quality
- Enhanced security for various applications
- Reduced costs and improved efficiency
- Application security strategy that eliminates unnecessary time and tasks

Tool-Based Assessment
Expanding application security coverage and
improving application security quality
- Prioritized scan results
- Optimal results
- Various vulnerability tests
- Deep experience and expertise

Automated Status Verification
Maximizing diagnostic tool utilization and
improving security through various best practices
- Automated security risk management reflecting real-world experience
- Practical results based on optimal workflows
- Applicable practical recommendations
Product Introduction
Key Functions
AMS Configuration Features and Components
· Role-based user management
· Scan site management
· Scan history, engine, and diagnostic statistics management
· Detailed scan result viewing
· Extension API – integration functions
· DevOps workflow support
· Connects AMS server with AS STD
· Management for simultaneous diagnosis of multiple sites
· AS STD function configuration and management
· Login Sequence configuration
· Multi-step operation configuration
· Diagnosis execution management and control
· Javascript/flash URL extraction and scanning
· URL extraction limitation capabilities
· Vulnerability scan result verification
· Error page configuration
· File exclusion functionality
· Multiple site simultaneous scanning
· Scan speed adjustment
· Multiple program execution
System Structure for Centralized Management and Efficient Vulnerability Scanning
Control Center for Managing Scan Engines
- · AMS server installation
- · Support for installation and management of additional scan agents for performance enhancement
- · Warranty and vulnerability advisory and correction suggestions
- · Script parsing and URL extraction engine
Various Levels of Reporting
- · International industry standard and compliance reports
- · User-based report access permissions
- · Dashboards and statistical reports for MGMT teams
Scan Engine
CodeOne
AMS
Enhancement Tools
- · Tunneling parsing, Windows capabilities
- · Tracking all possible paths
- · Scanning websites that support Active-X
- · Pre-post scan fluctuations and security concern functions
- · Very few errors and accurate analysis results
- · Detailed vulnerability/security recommendations
- · Usability with operational classification options
Testing Various Web Environments
- · Ticketing system for continuous management of identified problems
- · Status information to monitor the state of identified issues
Issues Tracking System
Web-based User Interface

AMS Dashboard
Product Introduction
Expected Benefits
Distribution of security vulnerability assessment responsibilities by business roles
Easier identification and efficient correction of issues within the web application delivery cycle
Centralized scan result management and report distribution
Extension of security testing to development/integration/quality management levels
Monitoring and control of web vulnerability scanning across the enterprise
Automatic storage and integration of scan results, allowing users to divide and aggregate vulnerabilities by business unit, geographic location, or third-party provider

