The application portfolio management (APM) discipline monitors the business, technical and cost fitness of the application portfolio. It uses factual information and analysis, allowing objective and transparent decisions. Its main objective is to identify, prioritize and propose opportunities to improve the portfolio. Opportunities include replacements, migration, modernization, consolidation and decommissioning. APM tools support the people, processes and information of the APM IT discipline to discover, monitor, analyze and visualize the fitness of the application portfolio and provide recommendations for improvement.
Gartner defines the application security testing (AST) market as consisting of providers of products that enable organizations to assess applications for the presence and management of risk. These products identify risk by evaluating source code, performing runtime tests and inspecting supply chain components. AST products can be integrated throughout development workflows for continuous assessment or be used to perform ad hoc evaluations. They enable organizations to manage application risks by providing an integrated set of capabilities for risk identification, prioritization and triage, policy evaluation and enforcement, and remediation assistance. Market offerings are available in on-premises, SaaS and hybrid delivery models. Organizations leverage AST products to assess applications for the presence of security vulnerabilities and other risks (e.g., legal and operational) throughout their life cycle. These assessments are used to measure and manage the risks within individual applications, application components or groups of applications in the context of their business criticality and other key attributes (e.g., environment, sensitive data handling, etc.). AST products further enable organizations to evaluate software for compliance with internal policies as well as regulatory requirements established by governments or authoritative industry groups.
Cloud management tooling enables organizations to manage hybrid and multicloud (that is, on-premises, public cloud and edge) services and resources. This includes providing governance, life cycle management, brokering and automation for managed cloud infrastructure resources across multiple functional areas. The tooling can be procured and operated by central IT organizations, such as I&O, cloud center of excellence (CCOE) and platform engineering/operations, or within specific lines of business. It can be deployed on-premises, in a customer’s public cloud account or purchased as a SaaS.
Gartner defines developer productivity insight platforms as solutions that provide software engineering leaders with data-driven visibility into the engineering team’s use of time and resources, operational effectiveness, and progress on deliverables. This enables software engineering leaders and their teams to make smarter business decisions, resulting in higher developer productivity. Developer productivity insight platforms must be capable of ingesting and analyzing the abundant data created by common engineering tools and systems. They must provide rich, tailored, and role-specific user experiences to help leaders more easily identify constraints, spot important trends, and gain contextual insights. Developer productivity insight platforms are used by software engineering leaders and their teams to better understand how software solutions are being built and delivered. Teams can more easily see where they are spending time, how they are approaching code quality (in the form of code reviews), and better understand team flow through key metrics like deployment frequency and cycle time. These platforms serve as a “single source of truth” for engineering process data, and provide a unified, comprehensive and transparent view of the engineering processes. Key engineering metrics for delivering digital products include team productivity and flow, business alignment, software quality, and operations effectiveness.
Gartner defines Software Composition Analysis (SCA) as a technology that analyzes applications and related artifacts (containers, registries, etc.) to detect open-source and third-party software components known to have security and functional vulnerabilities, are out-of-date for security patches, or that pose licensing risks. SCA products and services help ensure the enterprise software supply chain includes only secure components and, therefore, supports secure application development and assembly
Gartner defines the strategic portfolio management (SPM) market as comprising both cloud-based and on-premises applications for enterprisewide strategic planning and execution, supporting advanced portfolio management. SPM offerings integrate multiple portfolios with interdependent structures, creating a dynamic model of the path to realize strategic outcomes. These products are ideally suited for organizations pursuing digital strategies, which demand extensive stakeholder collaboration to continually adapt to changing conditions. Organizations use SPM to align portfolios with strategy and apply value-based decision making for ongoing flexibility in the midst of progress, disruptions and opportunities. Digital strategies combine portfolios representing different contexts, such as business capabilities, investments, applications, services, assets, programs, products and projects. Strategists, business leaders, IT leaders and PMOs cooperatively align the utilization of these diverse portfolios to progressively achieve strategic objectives.